OTL.Txt
OTL logfile created on: 7/1/2012 6:11:38 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = c:\Users\Jaskirat\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.99 Gb Total Physical Memory | 3.61 Gb Available Physical Memory | 72.40% Memory free
10.17 Gb Paging File | 8.74 Gb Available in Paging File | 85.93% Paging File free
Paging file location(s): c:\pagefile.sys 5409 7663 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687.57 Gb Total Space | 497.99 Gb Free Space | 72.43% Space Free | Partition Type: NTFS
Drive D: | 11.07 Gb Total Space | 1.04 Gb Free Space | 9.38% Space Free | Partition Type: NTFS
Computer Name: JASJIT-PC | User Name: Jaskirat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/01 16:22:41 | 000,595,968 | ---- | M] (OldTimer Tools) -- c:\Users\Jaskirat\Downloads\OTL.exe
PRC - [2011/05/20 10:10:26 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:
64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:
64bit: - [2011/08/11 19:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:
64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2007/10/18 11:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2012/06/14 16:23:34 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/05/08 17:24:49 | 000,661,600 | ---- | M] (Wellbia.com Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\SysWOW64\xsherlock.xem -- (xsherlock)
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/12 15:07:00 | 000,793,048 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2011/11/16 12:23:44 | 000,377,344 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2011/05/20 10:10:26 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/26 16:08:00 | 003,457,036 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2012/06/28 04:45:10 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\48651655.sys -- (48651655)
DRV:
64bit: - [2012/06/26 23:43:09 | 000,013,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SWDUMon.sys -- (SWDUMon)
DRV:
64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys -- (NisDrv)
DRV:
64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012/02/15 12:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011/08/11 08:57:38 | 000,023,464 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElRawDsk.sys -- (ElRawDisk)
DRV:
64bit: - [2011/07/22 12:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:
64bit: - [2011/07/12 17:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:
64bit: - [2011/05/20 09:53:44 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)
DRV:
64bit: - [2010/09/22 15:19:02 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\taphss.sys -- (taphss)
DRV:
64bit: - [2010/08/25 16:41:36 | 000,323,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:
64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2009/04/11 01:43:06 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usb8023.sys -- (USB_RNDIS)
DRV:
64bit: - [2009/02/26 19:46:34 | 010,276,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
DRV:
64bit: - [2008/09/09 21:19:36 | 000,025,888 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\PC-Doctor for Windows\pcd5srvc_x64.pkms -- (PCD5SRVC{8AAF211B-043E02A9-05040000})
DRV:
64bit: - [2008/05/08 13:27:00 | 000,411,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys -- (CAXHWBS2)
DRV:
64bit: - [2008/05/08 13:25:12 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys -- (winachsf)
DRV:
64bit: - [2008/05/08 13:24:08 | 001,487,872 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_DP.sys -- (HSF_DP)
DRV:
64bit: - [2008/03/26 13:27:22 | 000,026,624 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\RtNdPt60.sys -- (RtNdPt60)
DRV:
64bit: - [2007/10/18 11:37:10 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.sys -- (XAudio)
DRV:
64bit: - [2006/06/19 10:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - [2005/01/01 05:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
AOL.com - News, Sports, Weather, Entertainment, Stocks & Local
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
AOL.com - News, Sports, Weather, Entertainment, Stocks & Local
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about
:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
Startsearcher.com
IE - HKLM\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=smtrc&s={searchTerms}&f=4&hl={language}&src=chrm
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=tb50aoldesktopie7
IE - HKLM\..\SearchScopes\{4C37E074-8790-4D15-A405-ACAD40DA5C41}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{88157BB1-15A2-4788-8F2A-44E0B1A0CA7E}: "URL" = http://www.greatsearchnow.com/greatsearch.aspx?category=web&Toolbar_Id={928093D7-4ACD-4AE0-8962-6700FBAC762D}&query={searchTerms}
IE - HKLM\..\SearchScopes\{8F314B6F-48F2-41E3-AA62-B119D1F14741}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&systemid=1&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2680363
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
AOL.com - News, Sports, Weather, Entertainment, Stocks & Local
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
AOL.com - News, Sports, Weather, Entertainment, Local & Lifestyle
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
Startsearcher.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@Webzen.com/NPBrowserExt: C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN)
FF - HKLM\Software\MozillaPlugins\@Webzen.com/NPGameWebStarter: C:\Program Files (x86)\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll (WEBZEN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jaskirat\AppData\Roaming\mozilla\Firefox\extensions
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jaskirat\AppData\Roaming\mozilla\Firefox\extensions\textlinks@playsushi.com
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jaskirat\AppData\Local\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jaskirat\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jaskirat\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: WEBZEN Browser Extension (Enabled) = C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll
CHR - plugin: NPGameWebStarter (Enabled) = C:\Program Files (x86)\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: Angry Birds = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Gun Bros = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciamkmigckbgfajcieiflmkedohjjohh\2.0.1_0\
CHR - Extension: Soundtracker = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\codpnmnknnckampabeipflcgbnncjjhh\1.0.5_0\
CHR - Extension: Infected Mushroom = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\dobnnindgjlefbclgkdfgjaikcdiaone\3_0\
CHR - Extension: Timeline = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\efpffbikdalipombjoeeaclnmjcmbkgn\1.18.0_0\
CHR - Extension: PanicButton = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm\0.14.2.1_0\
CHR - Extension: AdBlock = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.37_0\
CHR - Extension: Troll Emoticons = C:\Users\Jaskirat\AppData\Local\Google\Chrome\User Data\Default\Extensions\hndllphbhpadfpoikpaofkkkpkpnmjik\4.6.7_0\
O1 HOSTS File: ([2012/06/25 20:03:42 | 000,442,859 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
全讯网,博彩优 ,皇 *网cr67com,皇 比分,皇 即时指数,太阳城代理112scg,tt娱乐城8bc8,网上真钱娱
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
www.1001namen.com
O1 - Hosts: 127.0.0.1
ͨ,,𱦲188,ͨ,ټ,ټ
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
100sexlinks.com - Sex links Resources and Information. This website is for sale!
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15217 more lines...
O2 - BHO: (GetDislike.BHO) - {2c28e48b-1d93-3aa7-8b5f-82576c04a7bb} - mscoree.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {6EDC3889-B841-4127-A2BF-C5FC48F972C7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A8864317-E18B-4292-99D9-E6E65AB905D3} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - CC:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - CC:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16:
64bit: - DPF: {3234EB1E-733E-4E6A-A8AB-EBB6287E5A7E}
http://content.systemrequirementslab...4_4.3.16.0.cab (Reg Error: Key error.)
O16:
64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/ge...sh/swflash.cab (Shockwave Flash Object)
O16 - DPF: {0CE0F418-1010-442D-871C-3454827DD539}
Web Page Under Construction (Reg Error: Value error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downlo...eckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CDACCF7-E28D-48C9-8492-A32B8A09DAF6}: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6CDACCF7-E28D-48C9-8492-A32B8A09DAF6}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF738EB5-7CC1-46A2-9526-F462DFBBD2B7}: DhcpNameServer = 24.29.103.15 24.29.103.16
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:
64bit: - Winlogon\Notify\WB: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Users\Jaskirat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jaskirat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29:
64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/01 16:16:54 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\Desktop\Jaskirat_2
[2012/06/30 19:03:03 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\Auslogics
[2012/06/29 23:14:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MalwareScanner
[2012/06/29 14:33:28 | 000,000,000 | ---D | C] -- C:\Restoration
[2012/06/29 14:30:08 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Local\APN
[2012/06/29 14:30:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eSupport.com
[2012/06/29 00:09:07 | 000,000,000 | ---D | C] -- C:\Program Files\Intel Corporation
[2012/06/29 00:05:13 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/06/27 23:55:32 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\GetRightToGo
[2012/06/27 23:54:11 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2012/06/27 23:14:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012/06/27 23:13:37 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\ConsumerSoft
[2012/06/27 23:12:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConsumerSoft
[2012/06/27 23:12:34 | 000,460,888 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\SysNative\drivers\48651655.sys
[2012/06/27 22:54:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/06/26 23:30:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2012/06/26 18:06:52 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\SUPERAntiSpyware.com
[2012/06/26 18:06:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012/06/26 18:06:16 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/06/26 16:28:45 | 000,323,176 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rtlh64.sys
[2012/06/26 00:09:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel Corporation
[2012/06/26 00:03:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/06/25 23:37:51 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\FixCleaner
[2012/06/25 23:37:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FixCleaner
[2012/06/25 23:37:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixCleaner
[2012/06/25 23:20:38 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Installers
[2012/06/25 19:16:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/06/25 19:15:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/24 20:19:16 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\WinBatch
[2012/06/23 17:02:20 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Roaming\Dropbox
[2012/06/17 12:26:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/06/17 12:22:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/17 12:20:57 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/06/15 17:13:31 | 000,000,000 | ---D | C] -- C:\Users\Jaskirat\AppData\Local\Macromedia
[2012/06/11 14:17:46 | 000,071,680 | ---- | C] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2012/06/11 14:17:42 | 000,065,536 | ---- | C] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/01 18:00:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/01 17:45:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/01 17:38:58 | 000,706,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/01 17:38:58 | 000,606,630 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/01 17:38:58 | 000,105,230 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/01 17:34:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1001UA.job
[2012/07/01 17:33:25 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 17:33:25 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/01 17:33:22 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/01 17:32:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/01 16:31:00 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1010Core.job
[2012/07/01 16:30:59 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1010UA.job
[2012/07/01 16:23:07 | 000,001,061 | ---- | M] () -- C:\Users\Jaskirat\Desktop\Revo Uninstaller.lnk
[2012/06/29 17:55:02 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForJaskirat.job
[2012/06/28 04:45:10 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\SysNative\drivers\48651655.sys
[2012/06/27 21:59:20 | 000,000,468 | ---- | M] () -- C:\Windows\tasks\FixCleaner Scan.job
[2012/06/27 21:59:20 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForJaskirat_2.job
[2012/06/26 23:43:09 | 000,013,920 | ---- | M] () -- C:\Windows\SysNative\drivers\SWDUMon.sys
[2012/06/26 18:06:25 | 000,001,758 | ---- | M] () -- C:\Users\Jaskirat\Desktop\SUPERAntiSpyware Professional.lnk
[2012/06/26 17:45:33 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/26 11:34:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1001Core.job
[2012/06/25 23:37:45 | 000,001,864 | ---- | M] () -- C:\Users\Public\Desktop\FixCleaner.lnk
[2012/06/25 20:03:42 | 000,442,859 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/06/25 20:02:33 | 000,442,859 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20120625-200342.backup
[2012/06/25 19:20:23 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/25 19:16:06 | 000,721,800 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/25 17:30:41 | 000,006,000 | ---- | M] () -- C:\Users\Jaskirat\AppData\Local\d3d9caps.dat
[2012/06/25 17:18:06 | 000,001,460 | ---- | M] () -- C:\Users\Jaskirat\AppData\Local\d3d9caps64.dat
[2012/06/22 16:24:52 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2012/06/17 12:26:24 | 000,001,718 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/17 12:22:24 | 000,001,656 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/14 11:32:45 | 000,417,640 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/11 22:36:17 | 000,002,059 | ---- | M] () -- C:\Users\Jaskirat\Desktop\Google Chrome.lnk
[2012/06/11 22:36:17 | 000,002,021 | ---- | M] () -- C:\Users\Jaskirat\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/06/11 14:17:46 | 000,071,680 | ---- | M] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2012/06/11 14:17:42 | 000,065,536 | ---- | M] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2012/06/10 21:04:42 | 000,002,611 | ---- | M] () -- C:\Users\Jaskirat\Desktop\Microsoft Office Word 2007.lnk
[2012/06/06 23:19:28 | 000,000,847 | ---- | M] () -- C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/27 17:06:25 | 000,000,354 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForJaskirat_2.job
[2012/06/26 23:30:12 | 000,001,061 | ---- | C] () -- C:\Users\Jaskirat\Desktop\Revo Uninstaller.lnk
[2012/06/26 18:06:25 | 000,001,758 | ---- | C] () -- C:\Users\Jaskirat\Desktop\SUPERAntiSpyware Professional.lnk
[2012/06/26 16:28:45 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2012/06/25 23:38:01 | 000,000,468 | ---- | C] () -- C:\Windows\tasks\FixCleaner Scan.job
[2012/06/25 23:37:45 | 000,001,864 | ---- | C] () -- C:\Users\Public\Desktop\FixCleaner.lnk
[2012/06/25 19:16:15 | 000,001,828 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/23 16:26:26 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1010UA.job
[2012/06/23 16:26:26 | 000,000,876 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2635976662-834253037-1513335141-1010Core.job
[2012/06/22 16:24:51 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2012/06/17 12:26:24 | 000,001,718 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/17 12:22:24 | 000,001,656 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/05/09 18:14:47 | 000,007,526 | -HS- | C] () -- C:\Users\Jaskirat\Folder.jpg
[2012/05/09 18:14:45 | 000,002,080 | -HS- | C] () -- C:\Users\Jaskirat\AlbumArtSmall.jpg
[2012/04/08 10:49:57 | 000,074,703 | ---- | C] () -- C:\Windows\SysWOW64mfc45.dll
[2012/01/24 19:29:08 | 000,000,000 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\{D52DF527-68BF-41AB-B62C-4395CC978769}
[2012/01/22 15:41:57 | 000,000,000 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\{EBAB8933-6BAA-4B10-AA3D-8EE249CB083C}
[2012/01/18 22:20:51 | 000,097,280 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\UrlManager.exe
[2012/01/18 22:20:51 | 000,002,405 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\urlManager.xml
[2011/09/25 19:39:08 | 000,000,111 | ---- | C] () -- C:\Windows\SysWow64\sysinter.drv
[2011/09/23 21:32:58 | 000,000,197 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/07/06 19:53:53 | 000,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/01/11 17:13:08 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011/01/11 15:28:52 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
[2011/01/01 15:43:55 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/12/31 00:28:27 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dll
[2010/12/20 23:42:21 | 000,721,800 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/06 22:32:36 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2010/12/06 22:32:03 | 000,000,248 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2010/12/06 22:32:01 | 000,000,891 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2009/05/29 18:49:26 | 000,055,296 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 17:09:42 | 000,000,552 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\d3d8caps.dat
[2009/03/08 21:39:26 | 000,006,000 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\d3d9caps.dat
[2009/02/28 21:39:30 | 000,001,460 | ---- | C] () -- C:\Users\Jaskirat\AppData\Local\d3d9caps64.dat
========== LOP Check ==========
[2010/02/07 20:19:39 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\acccore
[2011/06/22 08:17:18 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\AG Software
[2012/06/29 15:48:23 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Audacity
[2012/06/30 19:03:03 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Auslogics
[2012/06/29 15:48:23 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\BITS
[2009/03/03 17:56:13 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/06/27 23:13:37 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\ConsumerSoft
[2012/01/18 22:12:50 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\DemoCreator
[2012/06/24 08:03:20 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Dropbox
[2012/06/27 18:18:17 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\FixCleaner
[2010/12/06 22:32:20 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\FlashGet
[2010/12/06 22:32:18 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\FlashGetBHO
[2010/12/06 22:32:01 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\FlashgetSetup
[2011/01/26 18:03:54 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Genieo
[2012/06/27 23:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\GetRightToGo
[2010/12/08 18:16:05 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\GlobalMojo
[2012/06/29 15:48:24 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\IObit
[2012/06/29 15:48:24 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\iolo
[2011/04/16 15:02:45 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\MusicNet
[2012/05/24 20:19:56 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\muvee Technologies
[2010/08/01 18:52:59 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\NCH Swift Sound
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Panda Security
[2012/01/21 00:40:16 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Product_RM
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\rinsebyreal
[2011/02/27 23:52:52 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Sammsoft
[2010/12/31 00:13:22 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\spotmau
[2010/10/17 12:08:37 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\SupportSoft
[2012/06/29 00:07:15 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\SystemRequirementsLab
[2011/09/28 21:34:05 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Systweak
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\TS3Client
[2012/06/29 15:48:25 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\TuneUp Software
[2011/09/28 20:23:06 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\Uniblue
[2008/09/18 18:11:01 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\WildTangent
[2012/06/24 20:19:16 | 000,000,000 | ---D | M] -- C:\Users\Jaskirat\AppData\Roaming\WinBatch
[2012/06/27 21:59:20 | 000,000,468 | ---- | M] () -- C:\Windows\Tasks\FixCleaner Scan.job
[2010/03/14 10:38:56 | 000,000,456 | ---- | M] () -- C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2012/07/01 17:28:48 | 000,032,652 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ==========
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP

1B5B4F1
@Alternate Data Stream - 14 bytes -> C:\Windows\system.ini:c1_encryption_d
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP

06A4C76
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >