OTL.Txt
OTL logfile created on: 6/18/2011 9:12:32 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Ajith\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.87 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 63.45% Memory free
7.74 Gb Paging File | 6.28 Gb Available in Paging File | 81.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 231.32 Gb Total Space | 93.95 Gb Free Space | 40.61% Space Free | Partition Type: NTFS
Drive D: | 631.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: PC | User Name: Ajith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/18 21:11:39 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Ajith\Desktop\OTL.exe
PRC - [2011/04/18 17:40:08 | 002,334,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/03/22 13:37:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2011/03/21 13:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/02/24 21:08:34 | 000,566,688 | ---- | M] (Affinegy, Inc.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/02/24 21:08:32 | 007,034,272 | ---- | M] (Affinegy, Inc.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/02/24 21:08:32 | 001,770,400 | ---- | M] (Affinegy, Inc.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
PRC - [2011/01/10 14:05:38 | 000,603,896 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
PRC - [2010/04/01 04:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
========== Modules (SafeList) ==========
MOD - [2011/06/18 21:11:39 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Ajith\Desktop\OTL.exe
MOD - [2010/08/21 00:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/05/27 15:05:42 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:
64bit: - [2010/12/02 06:18:32 | 000,087,336 | ---- | M] (Dassault Systèmes SolidWorks Corp.) [On_Demand | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe -- (CoordinatorServiceHost)
SRV:
64bit: - [2010/10/06 20:19:20 | 000,094,472 | ---- | M] (Mentor Graphics Corporation) [On_Demand | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe -- (Remote Solver for Flow Simulation 2010)
SRV:
64bit: - [2010/02/11 00:29:30 | 000,952,320 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\Windows\SysNative\Ati2evxx.exe -- (Ati External Event Utility)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:
64bit: - [2009/03/27 18:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2011/06/10 02:30:53 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/05/27 15:23:42 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/05/27 15:05:44 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/24 21:08:34 | 000,566,688 | ---- | M] (Affinegy, Inc.) [Auto | Running] -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2011/01/10 14:05:38 | 000,603,896 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2010/10/22 13:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011/04/14 21:28:24 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV:
64bit: - [2011/04/05 00:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:
64bit: - [2011/03/16 16:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:
64bit: - [2011/03/11 01:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 01:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011/03/01 14:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:
64bit: - [2011/02/22 08:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:
64bit: - [2011/02/10 07:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV:
64bit: - [2011/01/10 13:52:06 | 000,022,752 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpnva64.sys -- (vpnva)
DRV:
64bit: - [2011/01/07 06:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:
64bit: - [2010/12/18 19:45:29 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:
64bit: - [2010/06/23 09:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2010/02/11 02:42:54 | 005,352,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2009/09/21 18:00:44 | 001,537,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:
64bit: - [2009/07/21 14:03:34 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2008/08/14 10:40:44 | 000,260,144 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2007/11/09 05:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F7 88 4B 24 B3 DE CB 01 [binary data]
IE - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.iastate.edu"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems:
smartwebprinting@hp.com:4.51
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2011/06/18 21:05:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/04/01 18:02:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/19 00:34:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/27 15:22:19 | 000,000,000 | ---D | M]
[2010/11/02 22:03:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ajith\AppData\Roaming\Mozilla\Extensions
[2011/05/27 02:13:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ajith\AppData\Roaming\Mozilla\Firefox\Profiles\d414knvk.default\extensions
[2011/01/02 03:53:21 | 000,000,914 | ---- | M] () -- C:\Users\Ajith\AppData\Roaming\Mozilla\Firefox\Profiles\d414knvk.default\searchplugins\dictionarycom.xml
[2010/12/19 22:38:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/11/04 18:44:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/19 22:38:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) --
[2011/06/18 21:05:01 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG10\FIREFOX4
() (No name found) -- C:\USERS\AJITH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\D414KNVK.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/05/05 20:15:23 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/11/04 18:31:36 | 000,274,432 | ---- | M] (Dassault Systèmes SolidWorks Corp.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npEModelPlugin.dll
[2011/03/22 13:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
[2011/05/05 20:15:25 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/18 20:13:12 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2896101978-3000554980-3934277194-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:
64bit: - Extra Button: PDFill PDF Editor - {ED93D107-B43A-490e-AA5C-C5578BAAF479} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/06/06 01:56:50 | 000,061,440 | R--- | M] () - D:\autoplay.exe -- [ CDFS ]
O32 - AutoRun File - [2001/07/23 07:25:04 | 000,000,047 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync) - C:\Program Files (x86)\AVG\AVG10\avgchsva.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart) - C:\Program Files (x86)\AVG\AVG10\avgrsa.exe (AVG Technologies CZ, s.r.o.)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/18 21:08:27 | 000,579,072 | ---- | C] (OldTimer Tools) -- C:\Users\Ajith\Desktop\OTL.exe
[2011/06/18 21:05:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011/06/18 21:04:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/06/18 21:03:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2011/06/18 20:44:12 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/06/18 19:57:58 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/06/18 19:57:58 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/06/18 19:57:58 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/06/18 19:57:49 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/06/18 19:57:44 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/18 19:51:19 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\AVG10
[2011/06/18 19:37:13 | 004,130,419 | R--- | C] (Swearware) -- C:\Users\Ajith\Desktop\ComboFix.exe
[2011/06/18 19:36:11 | 000,581,120 | ---- | C] (AVAST Software) -- C:\Users\Ajith\Desktop\aswMBR.exe
[2011/06/18 18:43:53 | 000,607,310 | R--- | C] (Swearware) -- C:\Users\Ajith\Desktop\dds.scr
[2011/06/18 16:25:14 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\Malwarebytes
[2011/06/18 16:25:09 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/18 16:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/18 16:25:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/18 16:25:06 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/06/18 16:25:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/17 16:04:09 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Desktop\tabpanel2
[2011/06/17 15:38:24 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Desktop\testgui
[2011/06/16 13:50:55 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Desktop\gui
[2011/06/16 12:36:03 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\EDrawings
[2011/06/16 12:35:47 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\DassaultSystemes
[2011/06/16 12:35:47 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Local\DassaultSystemes
[2011/06/16 12:35:47 | 000,000,000 | ---D | C] -- C:\ProgramData\DassaultSystemes
[2011/06/15 15:42:19 | 000,000,000 | ---D | C] -- C:\hotfix
[2011/06/12 03:33:30 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source 2010
[2011/06/11 02:07:16 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Documents\My Games
[2011/06/11 02:07:16 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Local\My Games
[2011/06/10 17:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/06/10 17:29:20 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/06/10 17:29:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/06/10 17:29:20 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/06/01 14:02:19 | 000,000,000 | R--D | C] -- C:\Users\Ajith\Dropbox
[2011/06/01 13:53:18 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\Dropbox
[2011/05/31 21:05:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Affinegy
[2011/05/31 21:01:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Belkin
[2011/05/31 20:43:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belkin
[2011/05/31 20:43:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belkin
[2011/05/30 22:18:07 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ys Typing Tutor
[2011/05/30 22:18:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ys Typing Tutor
[2011/05/30 22:18:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ys Typing Tutor
[2011/05/30 22:16:05 | 000,000,000 | ---D | C] -- C:\Ys
[2011/05/29 18:30:49 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Desktop\CAI Fixture
[2011/05/28 22:27:53 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warcraft III
[2011/05/28 22:27:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III
[2011/05/28 22:27:52 | 000,126,976 | ---- | C] (Blizzard Entertainment) -- C:\Windows\War3Unin.exe
[2011/05/28 22:22:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Warcraft III
[2011/05/27 15:23:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2011/05/27 15:22:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SolidWorks Corp
[2011/05/27 15:17:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2010
[2011/05/27 15:09:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SolidWorksx86
[2011/05/27 15:07:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2011/05/27 15:07:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SolidWorks Shared
[2011/05/27 15:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\SolidWorks Corp
[2011/05/27 15:07:28 | 000,000,000 | ---D | C] -- C:\ProgramData\SolidWorks
[2011/05/27 15:06:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks Installation Manager
[2011/05/27 15:05:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2011/05/27 15:05:18 | 000,000,000 | ---D | C] -- C:\SolidWorks Data (2)
[2011/05/27 14:47:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2011/05/27 14:35:39 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2011/05/27 11:54:06 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Documents\SolidWorks Visual Studio Tools for Applications
[2011/05/27 11:35:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2011/05/27 11:34:52 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Documents\Visual Studio 2005
[2011/05/27 11:34:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
[2011/05/27 11:33:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2011/05/27 11:31:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Shared
[2011/05/27 05:31:58 | 000,000,000 | ---D | C] -- C:\SolidWorks Data
[2011/05/27 05:26:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager
[2011/05/27 05:25:24 | 000,000,000 | ---D | C] -- C:\Users\Ajith\Documents\SolidWorks Downloads
[2011/05/27 05:25:24 | 000,000,000 | ---D | C] -- C:\Windows\SolidWorks
[2011/05/27 05:25:21 | 000,000,000 | ---D | C] -- C:\Users\Ajith\AppData\Roaming\SolidWorks
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/18 21:11:39 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Ajith\Desktop\OTL.exe
[2011/06/18 21:07:17 | 119,073,882 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/06/18 21:05:04 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/18 21:05:02 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/06/18 21:05:02 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/06/18 21:02:01 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2896101978-3000554980-3934277194-1001UA.job
[2011/06/18 20:24:39 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 20:24:39 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 20:13:12 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/06/18 20:12:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/18 20:12:35 | 3118,694,400 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/18 19:37:50 | 004,130,419 | R--- | M] (Swearware) -- C:\Users\Ajith\Desktop\ComboFix.exe
[2011/06/18 19:37:01 | 000,000,512 | ---- | M] () -- C:\Users\Ajith\Desktop\MBR.dat
[2011/06/18 19:36:13 | 000,581,120 | ---- | M] (AVAST Software) -- C:\Users\Ajith\Desktop\aswMBR.exe
[2011/06/18 18:43:46 | 000,607,310 | R--- | M] (Swearware) -- C:\Users\Ajith\Desktop\dds.scr
[2011/06/18 18:02:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2896101978-3000554980-3934277194-1001Core.job
[2011/06/18 17:41:30 | 000,302,592 | ---- | M] () -- C:\Users\Ajith\Desktop\yt9v2lmr.exe
[2011/06/18 16:26:20 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/18 16:26:20 | 000,624,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/18 16:26:20 | 000,106,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/17 14:59:41 | 000,435,752 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/11 01:16:10 | 000,002,124 | ---- | M] () -- C:\Users\Ajith\.recently-used.xbel
[2011/06/10 17:29:57 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/06/09 17:46:27 | 000,094,011 | ---- | M] () -- C:\Users\Ajith\Desktop\07-09256-00d.tif
[2011/06/01 14:45:08 | 000,034,875 | ---- | M] () -- C:\Users\Ajith\AppData\Local\Temp_table.xml
[2011/06/01 11:01:56 | 000,002,092 | -H-- | M] () -- C:\Users\Ajith\Documents\Default.rdp
[2011/05/29 17:23:12 | 000,001,483 | ---- | M] () -- C:\Users\Ajith\Desktop\fps.cfg
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/05/28 22:27:55 | 000,019,279 | ---- | M] () -- C:\Windows\War3Unin.dat
[2011/05/28 22:27:53 | 000,126,976 | ---- | M] (Blizzard Entertainment) -- C:\Windows\War3Unin.exe
[2011/05/28 22:27:53 | 000,002,829 | ---- | M] () -- C:\Windows\War3Unin.pif
[2011/05/27 15:23:40 | 000,002,803 | ---- | M] () -- C:\Users\Public\Desktop\PhotoView 360 2010.lnk
[2011/05/27 15:22:32 | 000,002,253 | ---- | M] () -- C:\Users\Ajith\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2011/05/27 15:22:32 | 000,002,229 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2010.lnk
[2011/05/27 15:17:03 | 000,002,635 | ---- | M] () -- C:\Users\Ajith\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2010 x64 Edition.lnk
[2011/05/27 15:17:03 | 000,002,611 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks 2010 x64 Edition.lnk
[2011/05/27 11:55:26 | 000,000,000 | ---- | M] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2011/05/27 11:53:47 | 000,000,023 | -H-- | M] () -- C:\Windows\yacht.xws
[2011/05/20 14:00:58 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/18 21:05:04 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/18 19:57:58 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/06/18 19:57:58 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/06/18 19:57:58 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/06/18 19:57:58 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/06/18 19:57:58 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/06/18 19:37:01 | 000,000,512 | ---- | C] () -- C:\Users\Ajith\Desktop\MBR.dat
[2011/06/18 17:41:20 | 000,302,592 | ---- | C] () -- C:\Users\Ajith\Desktop\yt9v2lmr.exe
[2011/06/11 01:16:10 | 000,002,124 | ---- | C] () -- C:\Users\Ajith\.recently-used.xbel
[2011/06/10 17:29:57 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/06/09 17:46:15 | 000,094,011 | ---- | C] () -- C:\Users\Ajith\Desktop\07-09256-00d.tif
[2011/05/29 23:42:40 | 000,034,875 | ---- | C] () -- C:\Users\Ajith\AppData\Local\Temp_table.xml
[2011/05/29 17:23:10 | 000,001,483 | ---- | C] () -- C:\Users\Ajith\Desktop\fps.cfg
[2011/05/28 22:27:53 | 000,019,279 | ---- | C] () -- C:\Windows\War3Unin.dat
[2011/05/28 22:27:53 | 000,002,829 | ---- | C] () -- C:\Windows\War3Unin.pif
[2011/05/27 15:23:40 | 000,002,803 | ---- | C] () -- C:\Users\Public\Desktop\PhotoView 360 2010.lnk
[2011/05/27 15:22:32 | 000,002,253 | ---- | C] () -- C:\Users\Ajith\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks eDrawings 2010.lnk
[2011/05/27 15:22:32 | 000,002,229 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2010.lnk
[2011/05/27 15:17:03 | 000,002,635 | ---- | C] () -- C:\Users\Ajith\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2010 x64 Edition.lnk
[2011/05/27 15:17:03 | 000,002,611 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks 2010 x64 Edition.lnk
[2011/05/27 11:55:26 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2011/05/27 11:53:47 | 000,000,023 | -H-- | C] () -- C:\Windows\yacht.xws
[2011/04/01 17:45:14 | 000,202,499 | ---- | C] () -- C:\Windows\hpoins18.dat
[2011/04/01 17:45:13 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2011/03/03 15:44:12 | 000,000,600 | ---- | C] () -- C:\Users\Ajith\AppData\Local\PUTTY.RND
[2010/11/02 21:37:27 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008/12/01 20:08:40 | 003,107,788 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.dat
========== LOP Check ==========
[2011/03/24 00:03:21 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\.minecraft
[2010/11/05 20:56:25 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\acccore
[2011/03/11 02:12:11 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Audacity
[2011/06/18 19:51:19 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\AVG10
[2010/12/19 01:48:14 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Cakewalk
[2010/12/18 23:29:16 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\DAEMON Tools Lite
[2011/06/16 12:35:47 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\DassaultSystemes
[2011/03/03 14:31:05 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Dev3DView
[2011/03/03 14:25:08 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\DevProf
[2011/06/01 14:04:05 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Dropbox
[2011/06/16 12:36:03 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\EDrawings
[2011/03/03 15:51:19 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\FileZilla
[2010/12/19 01:56:10 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\GetRightToGo
[2011/06/11 01:16:10 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\gtk-2.0
[2011/02/10 12:05:15 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Inspector
[2011/03/03 14:25:30 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\ProfiliXT
[2010/12/18 23:02:41 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\REAPER
[2010/12/19 22:12:27 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\Steinberg
[2011/05/27 02:18:37 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\SystemRequirementsLab
[2011/06/12 03:33:11 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\uTorrent
[2010/11/02 22:28:45 | 000,000,000 | ---D | M] -- C:\Users\Ajith\AppData\Roaming\WinBatch
[2011/03/29 12:23:23 | 000,032,572 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/06/18 20:22:23 | 000,017,097 | ---- | M] () -- C:\ComboFix.txt
[2011/06/18 20:12:35 | 3118,694,400 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/25 18:10:02 | 000,000,724 | -H-- | M] () -- C:\IPH.PH
[2006/12/01 23:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2011/06/18 20:12:35 | 4158,263,296 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/02 21:39:40 | 000,000,221 | -HS- | M] () -- C:\Users\Ajith\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/18 19:36:13 | 000,581,120 | ---- | M] (AVAST Software) -- C:\Users\Ajith\Desktop\aswMBR.exe
[2011/06/18 19:37:50 | 004,130,419 | R--- | M] (Swearware) -- C:\Users\Ajith\Desktop\ComboFix.exe
[2011/06/18 21:11:39 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Ajith\Desktop\OTL.exe
[2011/06/18 17:41:30 | 000,302,592 | ---- | M] () -- C:\Users\Ajith\Desktop\yt9v2lmr.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 16:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/11/02 21:38:38 | 000,000,402 | -HS- | M] () -- C:\Users\Ajith\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/04/01 18:05:13 | 000,001,265 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:29E09095
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:4DA0166C
< End of report >