This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help required removing searchqu.com

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

The homepage in my firefox browser has been set somehow as hxxp://www.searchqu.com and I am not able to remove it. I reckon it is some kind of a virus or something. Please help me getting rid of this problem. Its very annoying to see this page open every time I open a new tab. Pasted below are the OTL logs:

OTL logfile created on: 4/17/2011 10:20:40 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Punyasloka\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.56 Gb Total Space | 36.99 Gb Free Space | 37.91% Space Free | Partition Type: NTFS
Drive D: | 200.00 Gb Total Space | 29.32 Gb Free Space | 14.66% Space Free | Partition Type: NTFS
Drive E: | 168.10 Gb Total Space | 131.04 Gb Free Space | 77.95% Space Free | Partition Type: NTFS
Drive F: | 2.21 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: PUNYASLOKA-PC | User Name: Punyasloka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Punyasloka\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
PRC - C:\Program Files\Reliance Netconnect - Broadband+\bin\MonServiceUDisk.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
PRC - C:\Program Files\Microsoft Office Communicator\communicator.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Punyasloka\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Hamachi2Svc) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TunngleService) – C:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (NisSrv) – C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (UDisk Monitor) – C:\Program Files\Reliance Netconnect - Broadband+\bin\MonServiceUDisk.exe ()
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKslfac876b0) – C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4A04A528-149D-4724-B830-C7C66F344ED8}\MpKslfac876b0.sys (Microsoft Corporation)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (VIAHdAudAddService) – C:\Windows\System32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (ztemtusbser) – C:\Windows\System32\drivers\CT_ZTEMT_U_USBSER.sys (ZTEMT Incorporated)
DRV - (L1C) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
DRV - (tap0901t) TAP-Win32 Adapter V9 (Tunngle) – C:\Windows\System32\drivers\tap0901t.sys (Tunngle.net)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (hamachi) – C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (USBModem) – C:\Windows\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\Windows\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\Windows\System32\drivers\lgusbbus.sys (LG Electronics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.yahoo.com/?fr=fp-spt_gen
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://in.rediff.com/index.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://server.toolbar.rediff.com/toolbar/4…ml?mode=toolbar
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://in.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.co.in/"
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=405&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/24 13:14:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/17 09:50:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/17 09:50:21 | 000,000,000 | —D | M]

[2011/04/17 09:50:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Punyasloka\AppData\Roaming\Mozilla\Extensions
[2011/04/17 09:50:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Punyasloka\AppData\Roaming\Mozilla\Firefox\Profiles\sr34tbie.default\extensions
[2011/04/17 09:50:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/05 20:59:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/30 23:40:49 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/01/24 13:14:43 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/03/05 20:59:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/09 20:47:40 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2009/06/11 03:09:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (XBTBPos00 Class) - {BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} - File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [COMMUNICATOR] C:\Program Files\Microsoft Office Communicator\Communicator.exe (Microsoft Corporation)
O4 - HKCU..\Run: [googletalk] C:\Users\Punyasloka\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (C:\PROGRA~1\WI5C88~1\Datamngr\datamngr.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI5C88~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{072ed7a8-3b66-11e0-ba4a-6c626da8f9c0}\Shell - "" = AutoRun
O33 - MountPoints2\{072ed7a8-3b66-11e0-ba4a-6c626da8f9c0}\Shell\AutoRun\command - "" = G:\Startme.exe
O33 - MountPoints2\{38c052f9-23b4-11e0-bf93-6c626da8f9c0}\Shell - "" = AutoRun
O33 - MountPoints2\{38c052f9-23b4-11e0-bf93-6c626da8f9c0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{38c05300-23b4-11e0-bf93-6c626da8f9c0}\Shell - "" = AutoRun
O33 - MountPoints2\{38c05300-23b4-11e0-bf93-6c626da8f9c0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a1dfbc69-2263-11e0-864b-6c626da8f9c0}\Shell - "" = AutoRun
O33 - MountPoints2\{a1dfbc69-2263-11e0-864b-6c626da8f9c0}\Shell\AutoRun\command - "" = G:\Setup.exe /Auto
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\Windows\System32\lagarith.dll ( )
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)


========== Files/Folders - Created Within 30 Days ==========

[2013/08/01 19:48:54 | 000,143,872 | —- | C] (Intel Corporation) – C:\Windows\System32\iacenc.dll
[2011/05/18 12:38:01 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/05/18 11:46:13 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/05/18 11:39:07 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/05/18 11:38:38 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2011/05/17 23:16:53 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/17 23:16:53 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Searches
[2011/05/17 23:16:53 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/17 23:16:53 | 000,000,000 | -H-D | C] – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/17 23:16:45 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Roaming\Identities
[2011/05/17 23:16:44 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Contacts
[2011/05/17 23:16:39 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\VirtualStore
[2011/05/17 23:16:38 | 000,000,000 | –SD | C] – C:\Users\Punyasloka\AppData\Roaming\Microsoft
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Videos
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Saved Games
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Pictures
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Music
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Links
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Favorites
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Downloads
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\My Documents
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\Desktop
[2011/05/17 23:16:38 | 000,000,000 | R–D | C] – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\AppData\Local\Temporary Internet Files
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Templates
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Start Menu
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\SendTo
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Recent
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\PrintHood
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\NetHood
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Documents\My Videos
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Documents\My Pictures
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Documents\My Music
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\My Documents
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Local Settings
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\AppData\Local\History
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Cookies
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\Application Data
[2011/05/17 23:16:38 | 000,000,000 | -HSD | C] – C:\Users\Punyasloka\AppData\Local\Application Data
[2011/05/17 23:16:38 | 000,000,000 | -H-D | C] – C:\Users\Punyasloka\AppData
[2011/05/17 23:16:38 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\Temp
[2011/05/17 23:16:38 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\Microsoft
[2011/05/17 23:16:38 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Roaming\Media Center Programs
[2011/05/17 23:16:32 | 000,000,000 | -HSD | C] – C:\Recovery
[2011/04/17 10:16:37 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Punyasloka\Desktop\OTL.exe
[2011/04/17 09:50:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/04/16 20:14:04 | 000,026,176 | -H– | C] (LogMeIn, Inc.) – C:\Windows\System32\hamachi.sys
[2011/04/16 20:14:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/04/16 20:14:02 | 000,000,000 | —D | C] – C:\Program Files\LogMeIn Hamachi
[2011/04/16 20:11:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
[2011/04/16 20:11:33 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Tunngle
[2011/04/16 20:11:32 | 000,000,000 | —D | C] – C:\Program Files\Tunngle
[2011/04/16 14:09:17 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\LogMeIn Hamachi
[2011/04/14 10:12:03 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/14 10:12:03 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/14 10:11:59 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/14 10:11:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/14 10:11:58 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/14 10:11:54 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/14 10:11:54 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/14 10:11:54 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/14 10:11:54 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/14 10:11:53 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/14 10:11:53 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/14 10:11:53 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/14 10:11:53 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/14 10:11:53 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/14 10:11:53 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/14 10:11:53 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/14 10:11:04 | 002,331,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/14 10:11:00 | 000,191,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOVER.exe
[2011/04/14 10:10:57 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/04/14 10:10:52 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/14 10:10:52 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/14 10:09:33 | 000,000,000 | —D | C] – C:\Users\Punyasloka\Desktop\New folder
[2011/04/09 22:01:34 | 000,000,000 | —D | C] – C:\Users\Punyasloka\Desktop\New folder (2)
[2011/04/06 23:08:03 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\{FB197F5B-DA76-467D-A454-678705E53110}
[2011/04/05 23:38:01 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\{3706FB2C-1165-4B8A-B8C6-6A74FAE6DC9B}
[2011/04/02 20:19:59 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\{60B12FE0-1A1A-4559-BA8F-00EBEC7C76FC}
[2011/03/30 23:45:32 | 000,000,000 | —D | C] – C:\Users\Punyasloka\Documents\Freecorder
[2011/03/30 23:45:32 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\FLVService
[2011/03/30 23:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freecorder
[2011/03/30 23:45:27 | 000,000,000 | —D | C] – C:\Windows\Freecorder
[2011/03/30 23:45:27 | 000,000,000 | —D | C] – C:\Program Files\Freecorder
[2011/03/30 23:40:45 | 000,000,000 | —D | C] – C:\Program Files\Windows Savevid Toolbar
[2011/03/30 23:40:36 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Local\PackageAware
[2011/03/30 23:35:56 | 000,000,000 | —D | C] – C:\Windows\System32\appmgmt
[2011/03/30 18:41:57 | 003,088,482 | —- | C] (MyWebSearch.com) – C:\Users\Punyasloka\AppData\Local\mwsautSp.exe
[2011/03/30 18:26:08 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Roaming\Mozilla
[2011/03/28 21:30:13 | 000,000,000 | —D | C] – C:\Users\Punyasloka\Documents\Tunngle
[2011/03/28 21:30:13 | 000,000,000 | —D | C] – C:\Users\Punyasloka\AppData\Roaming\Tunngle
[2011/03/28 21:30:13 | 000,000,000 | —D | C] – C:\ProgramData\Tunngle
[2011/03/28 21:30:10 | 000,027,136 | —- | C] (Tunngle.net) – C:\Windows\System32\drivers\tap0901t.sys
[2011/03/19 11:50:06 | 000,000,000 | —D | C] – C:\Borland
[2011/03/19 11:36:35 | 000,000,000 | —D | C] – C:\TC
[2011/03/13 22:55:47 | 000,121,344 | —- | C] ( ) – C:\Windows\System32\lagarith.dll

========== Files - Modified Within 30 Days ==========

[2013/08/01 19:48:54 | 000,143,872 | —- | M] (Intel Corporation) – C:\Windows\System32\iacenc.dll
[2013/08/01 19:48:54 | 000,056,832 | —- | M] () – C:\Windows\System32\iyvu9_32.dll
[2011/05/18 11:40:59 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2011/04/17 10:16:52 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Punyasloka\Desktop\OTL.exe
[2011/04/17 09:50:23 | 000,001,873 | —- | M] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/17 09:50:23 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/17 09:47:22 | 000,017,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/17 09:47:22 | 000,017,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/17 09:44:25 | 000,626,040 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/17 09:44:25 | 000,107,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/17 09:39:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/17 09:39:40 | 2415,271,936 | -HS- | M] () – C:\hiberfil.sys
[2011/04/16 20:14:03 | 000,000,856 | —- | M] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/04/16 20:13:42 | 003,766,536 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/16 20:12:11 | 000,000,000 | —- | M] () – C:\Windows\System32\Access.dat
[2011/04/16 20:11:35 | 000,000,887 | —- | M] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Tunngle beta.lnk
[2011/04/16 20:11:35 | 000,000,863 | —- | M] () – C:\Users\Public\Desktop\Tunngle beta.lnk
[2011/04/15 08:34:12 | 000,014,848 | —- | M] () – C:\Users\Punyasloka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/14 10:12:11 | 000,000,990 | -HS- | M] () – C:\Users\Punyasloka\AppData\Roaming\systemfl.$dk
[2011/04/09 00:08:59 | 000,004,852 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\H3oIB6.full.jpeg
[2011/04/05 11:46:51 | 000,007,163 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\uGTg.full.jpeg
[2011/04/05 11:46:48 | 000,004,979 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\mLV7xq.full.jpeg
[2011/04/05 11:43:40 | 000,007,319 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\72XncB.full.jpeg
[2011/04/05 11:43:34 | 000,004,848 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\s0Mfp2.full.jpeg
[2011/04/05 11:43:32 | 000,004,974 | —- | M] () – C:\Users\Punyasloka\AppData\Roaming\Qh8RNS.full.jpeg
[2011/04/03 19:03:00 | 000,051,623 | —- | M] () – C:\Users\Punyasloka\Desktop\IJCA EB March 2010.pdf
[2011/04/02 13:07:14 | 000,265,536 | —- | M] () – C:\Users\Punyasloka\Desktop\Advertisement for admission to Ph.D & M.Tech(Res)_22032011.pdf
[2011/03/30 18:41:57 | 003,088,482 | —- | M] (MyWebSearch.com) – C:\Users\Punyasloka\AppData\Local\mwsautSp.exe

========== Files Created - No Company Name ==========

[2013/08/01 19:48:54 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2011/05/18 11:40:50 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/18 11:40:44 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/18 11:38:38 | 2415,271,936 | -HS- | C] () – C:\hiberfil.sys
[2011/05/17 23:16:54 | 000,001,417 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/17 23:16:38 | 000,000,290 | —- | C] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/17 23:16:38 | 000,000,272 | —- | C] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/04/17 09:50:23 | 000,001,873 | —- | C] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/17 09:50:23 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/16 20:11:35 | 000,000,887 | —- | C] () – C:\Users\Punyasloka\Application Data\Microsoft\Internet Explorer\Quick Launch\Tunngle beta.lnk
[2011/04/16 20:11:35 | 000,000,863 | —- | C] () – C:\Users\Public\Desktop\Tunngle beta.lnk
[2011/04/16 14:09:01 | 000,000,856 | —- | C] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/04/14 10:02:28 | 000,000,990 | -HS- | C] () – C:\Users\Punyasloka\AppData\Roaming\systemfl.$dk
[2011/04/09 00:08:59 | 000,004,852 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\H3oIB6.full.jpeg
[2011/04/05 11:46:51 | 000,007,163 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\uGTg.full.jpeg
[2011/04/05 11:46:48 | 000,004,979 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\mLV7xq.full.jpeg
[2011/04/05 11:43:40 | 000,007,319 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\72XncB.full.jpeg
[2011/04/05 11:43:34 | 000,004,848 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\s0Mfp2.full.jpeg
[2011/04/05 11:43:32 | 000,004,974 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\Qh8RNS.full.jpeg
[2011/04/03 19:03:00 | 000,051,623 | —- | C] () – C:\Users\Punyasloka\Desktop\IJCA EB March 2010.pdf
[2011/04/02 13:07:14 | 000,265,536 | —- | C] () – C:\Users\Punyasloka\Desktop\Advertisement for admission to Ph.D & M.Tech(Res)_22032011.pdf
[2011/03/28 21:30:58 | 000,000,000 | —- | C] () – C:\Windows\System32\Access.dat
[2011/03/13 22:55:49 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/03/13 22:55:47 | 000,810,496 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/03/13 22:55:47 | 000,183,808 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/03/13 22:55:46 | 000,080,896 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/03/13 21:33:31 | 000,000,031 | —- | C] () – C:\Windows\System32\datto4sini.dll
[2011/02/21 23:05:32 | 000,014,848 | —- | C] () – C:\Users\Punyasloka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/21 23:04:44 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/02/21 14:16:47 | 000,004,350 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\8NCS3R.full.jpeg
[2011/02/21 14:05:30 | 000,006,472 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\oorFUO.full.jpeg
[2011/02/07 20:12:26 | 000,004,788 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\gvc9qy.full.jpeg
[2011/02/07 19:39:16 | 000,004,974 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\V0ZXNz.full.jpeg
[2011/02/07 19:34:35 | 000,004,406 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\q8irYk.full.jpeg
[2011/02/07 14:43:45 | 000,008,863 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\VAC7Ns.full.jpeg
[2011/02/07 14:32:16 | 000,004,870 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\JQyEe1.full.jpeg
[2011/02/07 14:23:58 | 000,007,039 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\4isfn.full.jpeg
[2011/02/07 14:15:33 | 000,007,039 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\Vr02c.full.jpeg
[2011/02/07 14:14:04 | 000,004,345 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\DvEBbJ.full.jpeg
[2011/02/04 15:34:47 | 000,006,217 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\3TO5xk.full.jpeg
[2011/02/04 14:48:03 | 000,004,157 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\zEGij8.full.jpeg
[2011/02/03 21:15:19 | 000,004,758 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\B7L7gk.full.jpeg
[2011/02/03 20:07:18 | 000,010,214 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\BGx93T.full.jpeg
[2011/01/23 02:59:52 | 000,000,127 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\default.rss
[2011/01/18 15:08:44 | 000,008,845 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\ob9jv3.full.jpeg
[2011/01/18 15:03:43 | 000,005,820 | —- | C] () – C:\Users\Punyasloka\AppData\Roaming\default.full.jpeg
[2009/07/14 10:27:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 10:03:53 | 003,766,536 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 07:35:48 | 000,626,040 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 07:35:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 07:35:48 | 000,107,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 07:35:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 07:35:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 07:34:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 05:49:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 05:25:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 05:21:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 05:12:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 02:56:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2011/01/18 15:00:20 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\AvatarCache
[2011/01/18 23:40:51 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\GetRightToGo
[2011/01/18 15:00:16 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\Rediff Bol
[2011/01/18 15:00:16 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\Rediff.com
[2011/04/16 20:11:42 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\Tunngle
[2011/04/17 10:22:04 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\uTorrent
[2011/01/18 15:00:16 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\WallpaperCache
[2011/01/19 19:29:09 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\ZTEEVDO
[2011/01/19 19:25:45 | 000,000,000 | —D | M] – C:\Users\Punyasloka\AppData\Roaming\ZTEMTUI
[2011/03/10 08:38:53 | 000,032,630 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 03:12:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/04/17 09:39:40 | 2415,271,936 | -HS- | M] () – C:\hiberfil.sys
[2011/01/18 23:52:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/01/18 23:52:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/04/17 09:39:47 | 3220,365,312 | -HS- | M] () – C:\pagefile.sys
[2011/04/14 10:11:49 | 000,000,655 | —- | M] () – C:\Sys_LogWin.log

< %systemroot%\Fonts\*.com >
[2009/07/14 10:22:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 10:22:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 10:22:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 10:22:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 03:01:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 06:45:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 06:46:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 10:11:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >
[2011/01/20 23:37:11 | 000,000,000 | —D | M] – C:\Program Files\Superbike Racing\belgium\bak

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/14 10:07:42 | 000,000,146 | -HS- | M] () – C:\Users\Punyasloka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/04/17 10:16:52 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Punyasloka\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-15 21:30:50

< End of report >

================================================================================
=============================================================

OTL Extras logfile created on: 4/17/2011 10:20:40 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Punyasloka\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.56 Gb Total Space | 36.99 Gb Free Space | 37.91% Space Free | Partition Type: NTFS
Drive D: | 200.00 Gb Total Space | 29.32 Gb Free Space | 14.66% Space Free | Partition Type: NTFS
Drive E: | 168.10 Gb Total Space | 131.04 Gb Free Space | 77.95% Space Free | Partition Type: NTFS
Drive F: | 2.21 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: PUNYASLOKA-PC | User Name: Punyasloka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{28a0e389-e0bb-406b-ac4e-10edaedc4e98}" = Nero 9 Essentials
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45FCADDB-0B29-457E-83A1-D245C62A716C}" = OLYMPUS Master 2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{491DFBAA-77EF-4B06-8676-2FC66EEE049A}" = LogMeIn Hamachi
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision Help
"{605A10E3-9117-42AB-9349-FB0C4B3D2F66}" = Superbike Racing
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{ADE91A13-434D-4229-00BC-182BAD607303}" = Need for Speed™ Most Wanted
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b86754dd-2ddb-4ac0-9015-cb487277254e}" = InCD Help
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5BA0430-919F-46DD-B656-0796F8A5ADFF}" = Microsoft Office Communicator 2007
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"4Videosoft MKV Video Converter_is1" = 4Videosoft MKV Video Converter
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DVD Cutter_is1" = DVD Cutter 1.7
"Freecorder4.12" = Freecorder 4
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"IsoBuster_is1" = IsoBuster 2.8.5
"jet_fighter_2015_usa" = JETFIGHTER 2015
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.9.0 (Full)
"LogMeIn Hamachi" = LogMeIn Hamachi
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MP3 Cutter_is1" = MP3 Cutter 1.6
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"RealPlayer 12.0" = RealPlayer
"Rediff Bol" = Rediff Bol
"Searchqu 405 MediaBar" = Windows Savevid Toolbar
"Super Mario 3 : Mario Forever" = Super Mario 3 : Mario Forever
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"VLC media player" = VideoLAN VLC media player 0.8.6h
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZTEWireless-101_is1" = Reliance Netconnect - Broadband+

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/12/2011 4:38:31 PM | Computer Name = Punyasloka-PC | Source = TnglCtrl.exe | ID = 0
Description =

Error - 4/12/2011 4:38:31 PM | Computer Name = Punyasloka-PC | Source = TnglCtrl.exe | ID = 0
Description =

Error - 4/12/2011 4:38:31 PM | Computer Name = Punyasloka-PC | Source = TnglCtrl.exe | ID = 0
Description =

Error - 4/13/2011 12:51:32 PM | Computer Name = Punyasloka-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

Error - 4/14/2011 1:01:01 PM | Computer Name = Punyasloka-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

Error - 4/14/2011 10:34:03 PM | Computer Name = Punyasloka-PC | Source = Application Hang | ID = 1002
Description = The program uTorrent.exe version 2.2.0.23703 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: ba4 Start
Time: 01cbfab389c2a9b8 Termination Time: 21770 Application Path: C:\Program Files\uTorrent\uTorrent.exe

Report
Id: b179bed4-6708-11e0-bb68-6c626da8f9c0

Error - 4/15/2011 7:28:42 PM | Computer Name = Punyasloka-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

Error - 4/16/2011 4:57:57 AM | Computer Name = Punyasloka-PC | Source = Communicator | ID = 15728643
Description = Communicator was unable to resolve the DNS hostname of the login server
sipinternal.cognizant.com. Resolution: If you are using manual configuration for
Communicator, please check that the server name is typed correctly and in full.
If you are using automatic configuration, the network administrator will need to
double-check the DNS A record configuration for sipinternal.cognizant.com because
it could not be resolved.

Error - 4/16/2011 4:58:27 AM | Computer Name = Punyasloka-PC | Source = Communicator | ID = 15728643
Description = Communicator was unable to resolve the DNS hostname of the login server
sipinternal.cognizant.com. Resolution: If you are using manual configuration for
Communicator, please check that the server name is typed correctly and in full.
If you are using automatic configuration, the network administrator will need to
double-check the DNS A record configuration for sipinternal.cognizant.com because
it could not be resolved.

Error - 4/16/2011 4:58:27 AM | Computer Name = Punyasloka-PC | Source = Communicator | ID = 15728643
Description = Communicator was unable to resolve the DNS hostname of the login server
sip.cognizant.com. Resolution: If you are using manual configuration for Communicator,
please check that the server name is typed correctly and in full. If you are using
automatic configuration, the network administrator will need to double-check the
DNS A record configuration for sip.cognizant.com because it could not be resolved.

[ Media Center Events ]
Error - 4/12/2011 6:17:12 AM | Computer Name = Punyasloka-PC | Source = MCUpdate | ID = 0
Description = 3:47:08 PM - Error connecting to the internet. 3:47:08 PM - Unable
to contact server..

Error - 4/15/2011 6:20:41 PM | Computer Name = Punyasloka-PC | Source = MCUpdate | ID = 0
Description = 3:50:41 AM - Error connecting to the internet. 3:50:41 AM - Unable
to contact server..

Error - 4/15/2011 6:21:16 PM | Computer Name = Punyasloka-PC | Source = MCUpdate | ID = 0
Description = 3:51:11 AM - Error connecting to the internet. 3:51:11 AM - Unable
to contact server..

[ System Events ]
Error - 4/12/2011 8:23:24 AM | Computer Name = Punyasloka-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:51:38 PM on ?4/?12/?2011 was unexpected.

Error - 4/12/2011 12:06:59 PM | Computer Name = Punyasloka-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:34:30 PM on ?4/?12/?2011 was unexpected.

Error - 4/15/2011 11:50:38 AM | Computer Name = Punyasloka-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:03:24 PM on ?4/?15/?2011 was unexpected.

Error - 4/15/2011 12:16:25 PM | Computer Name = Punyasloka-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:44:33 PM on ?4/?15/?2011 was unexpected.

Error - 4/16/2011 4:39:11 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7030
Description = The LogMeIn Hamachi 2.0 Tunneling Engine service is marked as an interactive
service. However, the system is configured to not allow interactive services.
This service may not function properly.

Error - 4/16/2011 4:39:11 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Hamachi 2.0 Tunneling Engine service to connect.

Error - 4/16/2011 4:39:11 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Hamachi 2.0 Tunneling Engine service failed to start due
to the following error: %%1053

Error - 4/16/2011 10:44:05 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7030
Description = The LogMeIn Hamachi 2.0 Tunneling Engine service is marked as an interactive
service. However, the system is configured to not allow interactive services.
This service may not function properly.

Error - 4/16/2011 10:44:06 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Hamachi 2.0 Tunneling Engine service to connect.

Error - 4/16/2011 10:44:06 AM | Computer Name = Punyasloka-PC | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Hamachi 2.0 Tunneling Engine service failed to start due
to the following error: %%1053


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, bibhubrata

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

——————————————————————————–

With this being Win7 - Windows7 has a very robust System Restore, and as such - is always my first recommendation. Try going back to a point a day or so before the event, and see how things are. Use Method 2, Through System Recovery Options at Boot, for running System Restore as shown in this link System Restore - Windows 7 Forums (scroll down a bit to find Method 2)

Let me know how that worked out for you.

——————————————————————————–

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, bibhubrata

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

——————————————————————————–

With this being Win7 - Windows7 has a very robust System Restore, and as such - is always my first recommendation. Try going back to a point a day or so before the event, and see how things are. Use Method 2, Through System Recovery Options at Boot, for running System Restore as shown in this link System Restore - Windows 7 Forums (scroll down a bit to find Method 2)

Let me know how that worked out for you.

——————————————————————————–

Hi Conspire, Sorry, the previous post was posted by mistake and thank you for your response. I tried system recovery as directed by you. But I am afraid it didn't resolve the issue. The problem is it has been months this problem is there and system recovery doesn't show up recovery points beyond few days. Anyways, the bottom line is that the problem still persists :(. I think we will have to find a alternative way to remove this virus or whatever. And I might not be able to reply till 2nd week of May. Kindly bear with me. Thanks again, Bibhu

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI