This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu Malware

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ummm, IDK how to start this thread so I'll just continue on explaining the problem I have right now. Sorry if I'm being rude since English isn't my main language and I don't know much about how to write in appropriate manner. Some days ago my computer which is also used by my family got this searchqu toolbar and it has been annoying me since then. At May 15th, one my of my family member accidentally clicked on something that triggers the installation of iLivid. My Firefox 3.6.3 homepage suddenly changed into searchqu toolbar, changed it back and I think the problem is done. Then whenever I open a new blank tab, the searchqu search page always appear, which I feel really annoying. Some of my webs also got problems, usually redirected to other pages, which is the most annoying problem. I tried to install Firefox 4.0.1 and the searchqu is lost. However because the new firefox doesn't support IDM, I uninstall it and install the 3.6.3 version. The searchqu problem is back once again. Now I use the firefox 4.0.1 to minimalize the problem. I seacrh in the Internet and I found this site has been able to fix the problems with searchqu toolbar. Thanks before if you're willing to help me, again I'm sorry if I'm being rude. Please help me.
I have downloaded OTL and this is the log, will post the extras.txt in the next reply:
OTL logfile created on: 19/05/2011 15:05:13 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,84 Gb Free Space | 50,70% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS

Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Windows\VM30xSnap.exe (Vimicro)


========== Modules (SafeList) ==========

MOD - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Internet Download Manager\idmmkb.dll (Tonec Inc.)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfPCI) – C:\Windows\SysNative\drivers\VSTBS26.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysNative\drivers\vm30xx64.sys (Vimicro Corporation)
DRV - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysWOW64\drivers\vm30xx64.sys (Vimicro Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://id.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F9 F5 E8 31 0F CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.id/"
FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.http: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/18 22:34:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/18 22:34:07 | 000,000,000 | —D | M]

[2011/05/15 23:30:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Extensions
[2011/05/16 17:12:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\extensions
[2011/05/18 22:34:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/10 08:41:26 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) –
[2011/04/14 23:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 15:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/11 04:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [VM30xSnap] C:\Windows\VM30xSnap.exe (Vimicro)
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: vidc.MP42 - MPG4c32.dll File not found
Drivers32: vidc.MP43 - MPG4c32.dll File not found
Drivers32: vidc.MPG4 - MPG4c32.dll File not found
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/19 14:58:35 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\index.php_files
[2011/05/18 22:05:21 | 012,521,992 | —- | C] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/05/15 23:27:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\PackageAware
[2011/05/14 14:12:07 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2011/05/14 14:12:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe Systems Shared
[2011/05/14 13:39:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
[2011/05/14 13:39:43 | 000,000,000 | —D | C] – C:\ProgramData\UDL
[2011/05/14 13:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Print CD
[2011/05/14 13:38:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON Print CD
[2011/05/14 13:37:04 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2011/05/14 13:37:04 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2011/05/14 13:37:04 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2011/05/14 13:37:04 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2011/05/14 13:37:04 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2011/05/14 13:36:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON
[2011/05/14 13:36:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2011/05/14 13:36:46 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2011/05/14 13:34:08 | 000,008,704 | —- | C] (SEIKO EPSON CORP.) – C:\Windows\SysNative\E_GCINST.DLL
[2011/05/14 13:34:05 | 000,129,536 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_ILMCKP.DLL
[2011/05/14 13:34:05 | 000,086,528 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_IBCBCKP.DLL
[2011/05/14 13:33:59 | 000,000,000 | —D | C] – C:\Program Files\EPSON
[2011/05/14 07:09:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/12 12:22:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple Computer
[2011/05/12 12:22:08 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Apple Computer
[2011/05/12 12:22:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/12 12:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/12 12:20:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/12 12:20:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\skypePM
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/05/10 08:40:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/05/10 08:27:52 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Skype
[2011/05/10 08:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/05/10 08:17:37 | 000,000,000 | —D | C] – C:\Lenovo Camera
[2011/05/10 08:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Camera
[2011/05/10 08:17:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Filter
[2011/05/10 08:17:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lenovo Camera
[2011/05/10 08:13:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vimicro USB PC Camera (ZC030x)
[2011/05/10 08:13:40 | 001,330,688 | —- | C] (Vimicro Corporation) – C:\Windows\SysNative\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 001,330,688 | R— | C] (Vimicro Corporation) – C:\Windows\SysWow64\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 000,249,856 | R— | C] (Vimicro) – C:\Windows\SysWow64\VM30xPRP.Ax
[2011/05/10 08:13:39 | 000,057,344 | R— | C] (Vimicro ) – C:\Windows\vm30xcap.exe
[2011/05/10 08:13:39 | 000,053,248 | R— | C] (Vimicro) – C:\Windows\VM30xSnap.exe
[2011/05/10 08:13:35 | 000,023,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drivers\usbcamd2.sys
[2011/05/10 08:13:34 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/10 08:13:34 | 000,348,160 | R— | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/10 08:12:57 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\InstallShield
[2011/05/09 10:10:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 6
[2011/05/09 09:59:13 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/05/09 09:21:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2011/05/09 09:21:07 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/05/09 09:20:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2011/05/09 09:20:58 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2011/05/09 09:19:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\PcSetup
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\DVDFab
[2011/05/08 22:17:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 6
[2011/05/08 13:20:43 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Games
[2011/05/08 12:35:03 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/08 11:41:05 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Macromedia
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Adobe
[2011/05/08 09:54:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\Downloads
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Internet Download Manager
[2011/05/08 09:28:51 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\LogMeIn Hamachi
[2011/05/08 09:28:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2011/05/08 09:24:35 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/08 07:00:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Mozilla
[2011/05/08 06:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/08 06:44:13 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/08 06:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2011/05/08 06:44:09 | 000,000,000 | —D | C] – C:\Program Files\TeraCopy
[2011/05/08 06:43:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ACDSee
[2011/05/08 06:43:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\ProgramData\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\ACD Systems
[2011/05/08 06:42:10 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/05/08 06:41:10 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/08 06:41:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/08 06:39:58 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Adobe
[2011/05/08 06:38:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Player Classic
[2011/05/08 06:37:55 | 000,839,680 | —- | C] (http://www.mp3dev.org/) – C:\Windows\SysWow64\lameACM.acm
[2011/05/08 06:37:55 | 000,287,744 | —- | C] (Kristal StudioDFileDescription) – C:\Windows\SysWow64\divxa32.acm
[2011/05/08 06:37:55 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\SysWow64\mp3fhg.acm
[2011/05/08 06:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/05/08 06:37:54 | 000,630,784 | —- | C] (On2.com) – C:\Windows\SysWow64\vp7vfw.dll
[2011/05/08 06:37:54 | 000,391,680 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\I263_32.drv
[2011/05/08 06:37:54 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/05/08 06:37:54 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\SysWow64\ac3acm.acm
[2011/05/08 06:37:54 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[2011/05/08 06:37:54 | 000,039,936 | —- | C] (Disappearing Inc.) – C:\Windows\SysWow64\huffyuv.dll
[2011/05/08 06:37:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\K-Lite Codec Pack
[2011/05/08 06:37:02 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\ashampoo
[2011/05/08 06:36:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ashampoo
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/05/08 06:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/08 06:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/08 06:29:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/08 06:28:50 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Help
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/05/08 06:28:42 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/05/08 06:28:26 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Searches
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/08 06:10:38 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/08 06:10:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Identities
[2011/05/08 06:10:04 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Contacts
[2011/05/08 06:10:00 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\VirtualStore
[2011/05/08 06:09:30 | 000,000,000 | –SD | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Videos
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Saved Games
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Pictures
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Music
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Links
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Favorites
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Downloads
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Desktop
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Temporary Internet Files
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Templates
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Start Menu
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\SendTo
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Recent
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\PrintHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\NetHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Videos
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Pictures
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Music
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Local Settings
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\History
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Cookies
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\AppData
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Temp
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Center Programs
[2011/05/08 06:09:03 | 000,000,000 | -HSD | C] – C:\Recovery
[2011/05/07 16:04:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/05/07 16:01:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/05/07 16:01:07 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/19 14:33:25 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 14:33:25 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 14:30:53 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/19 14:30:53 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/19 14:30:53 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/19 14:26:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/19 14:26:09 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/18 23:06:18 | 000,297,791 | —- | M] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:34:22 | 000,002,052 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 22:34:08 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/18 22:13:42 | 012,521,992 | —- | M] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/14 20:02:17 | 001,660,864 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 20:01:47 | 001,648,820 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 20:01:09 | 001,743,628 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 19:59:55 | 001,647,664 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 19:57:51 | 000,002,058 | —- | M] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:24 | 030,476,905 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 13:33:48 | 000,000,025 | —- | M] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/12 12:09:50 | 000,000,016 | —- | M] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:44:51 | 000,000,056 | -H– | M] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:40:47 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:29:56 | 000,000,937 | —- | M] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/10 08:17:21 | 000,001,918 | —- | M] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/09 10:10:44 | 000,099,384 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/09 10:10:44 | 000,082,816 | —- | M] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/09 10:10:44 | 000,007,859 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/09 10:10:44 | 000,001,167 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/09 10:10:42 | 000,000,955 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | M] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/08 22:17:49 | 000,082,816 | —- | M] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 09:46:25 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 09:08:12 | 000,341,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/08 06:45:22 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:36:15 | 000,001,166 | —- | M] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiicdxx.dat

========== Files Created - No Company Name ==========

[2011/05/18 23:06:14 | 000,297,791 | —- | C] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:34:08 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/18 22:29:28 | 000,002,052 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 22:29:28 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/14 19:57:51 | 000,002,058 | —- | C] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:22 | 030,476,905 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:12:04 | 000,002,065 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS.lnk
[2011/05/14 14:12:04 | 000,002,058 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 14:09:12 | 001,660,864 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 14:09:00 | 001,648,820 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 14:07:52 | 001,743,628 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 14:07:28 | 001,647,664 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 13:37:04 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/05/14 13:37:04 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2011/05/14 13:37:04 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2011/05/14 13:37:04 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2011/05/14 13:37:04 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2011/05/14 13:37:04 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2011/05/14 13:37:04 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2011/05/14 13:37:04 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2011/05/14 13:37:04 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2011/05/14 13:37:04 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2011/05/14 13:37:04 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2011/05/14 13:37:04 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2011/05/14 13:37:04 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2011/05/14 13:37:04 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2011/05/14 13:37:04 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2011/05/14 13:37:04 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2011/05/14 13:37:04 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2011/05/14 13:37:04 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2011/05/14 13:37:04 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/05/14 13:37:04 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/05/14 13:37:04 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2011/05/14 13:37:04 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2011/05/14 13:37:04 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/05/14 13:37:04 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2011/05/14 13:33:48 | 000,000,025 | —- | C] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/14 07:09:08 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/12 12:20:37 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/10 08:44:51 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:27:21 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:17:42 | 000,000,016 | —- | C] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:17:21 | 000,001,918 | —- | C] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/10 08:13:39 | 000,049,152 | R— | C] () – C:\Windows\amcap.exe
[2011/05/10 08:13:36 | 000,138,752 | —- | C] () – C:\Windows\VM303Uninst64.exe
[2011/05/10 08:13:36 | 000,073,728 | —- | C] () – C:\Windows\VMInstNT.exe
[2011/05/10 08:13:36 | 000,069,632 | —- | C] () – C:\Windows\VMInst64.exe
[2011/05/10 08:13:35 | 000,040,960 | —- | C] () – C:\Windows\VM303UninstNT.exe
[2011/05/09 10:10:42 | 000,000,955 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | C] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/09 09:08:52 | 000,000,937 | —- | C] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/08 22:17:49 | 000,099,384 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/08 22:17:49 | 000,007,859 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/08 22:17:49 | 000,001,167 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/08 09:46:25 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 06:45:22 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:37:55 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/05/08 06:37:55 | 000,000,414 | —- | C] () – C:\Windows\SysWow64\lame_acm.xml
[2011/05/08 06:37:55 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/05/08 06:37:54 | 002,600,448 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/05/08 06:37:54 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/08 06:37:54 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/08 06:37:54 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/05/08 06:36:15 | 000,001,166 | —- | C] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/08 06:10:55 | 000,001,409 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/08 06:10:41 | 000,001,443 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/08 06:09:30 | 000,000,290 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/08 06:09:30 | 000,000,272 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/07 16:04:59 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/07 16:04:48 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2011/05/07 16:01:07 | 1608,179,712 | -HS- | C] () – C:\hiberfil.sys
[2009/07/14 12:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 09:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 09:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 07:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 06:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 04:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 04:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2002/03/22 05:39:02 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\UNACEV2.DLL

========== LOP Check ==========

[2011/05/08 06:43:13 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:37:02 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/19 14:26:28 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/15 23:27:17 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/12 12:25:20 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/08 12:35:03 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/14 19:59:05 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/09 10:10:47 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2009/07/14 12:08:49 | 000,014,216 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/05/19 14:26:09 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 14:26:11 | 2144,239,616 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 12:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 12:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 12:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 12:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 03:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 11:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/08 06:38:01 | 000,000,221 | -HS- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
This is the Extra log:
OTL Extras logfile created on: 19/05/2011 15:05:13 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,84 Gb Free Space | 50,70% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS

Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"TeraCopy_is1" = TeraCopy 2.12

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{133EE96D-DBA6-4644-84A4-B2794505D669}" = Vimicro USB PC Camera
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B0625F16-B742-4F75-9FD8-20B47ACC7DE2}" = ACDSee 7.0 PowerPack
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{BBF79EFA-3F63-43BC-88EE-0157CE50F1B1}" = Lenovo Camera
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ashampoo Burning Studio 8_is1" = Ashampoo Burning Studio 8.03
"DVDFab 6_is1" = DVDFab 6.2.0.5 (11/11/2009)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Stylus Photo R285_290 User’s Guide" = EPSON Stylus Photo R285_290 Manual
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.0.0
"LogMeIn Hamachi" = LogMeIn Hamachi
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/05/2011 22:25:28 | Computer Name = Nyoo-PC | Source = MsiInstaller | ID = 10005
Description = Product: LogMeIn Hamachi – A newer version (2.0.3.111) of Hamachi
has been found on the system. To downgrade, uninstall before proceeding.

Error - 07/05/2011 22:25:40 | Computer Name = Nyoo-PC | Source = MsiInstaller | ID = 10005
Description = Product: LogMeIn Hamachi – A newer version (2.0.3.111) of Hamachi
has been found on the system. To downgrade, uninstall before proceeding.

Error - 14/05/2011 2:59:36 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0x3cc Faulting application
start time: 0x01cc12047bcccb34 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: ba4149ab-7df7-11e0-80b7-001cc0ae3591

Error - 14/05/2011 3:00:08 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0x534 Faulting application
start time: 0x01cc12048f34a310 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: ccfb5d13-7df7-11e0-80b7-001cc0ae3591

Error - 14/05/2011 3:14:42 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0xc4 Faulting application
start time: 0x01cc120698294845 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: d61879ad-7df9-11e0-80b7-001cc0ae3591

Error - 18/05/2011 11:26:54 | Computer Name = Nyoo-PC | Source = Application Hang | ID = 1002
Description = The program Searchqu Toolbar uninstall.exe version 4.1.0.1 stopped
interacting with Windows and was closed. To see if more information about the problem
is available, check the problem history in the Action Center control panel. Process
ID: fe4 Start Time: 01cc156fc43f0347 Termination Time: 0 Application Path: C:\Users\NYOO'S~1\AppData\Local\Temp\nso747A.tmp\Searchqu
Toolbar uninstall.exe Report Id:

[ Media Center Events ]
Error - 07/05/2011 19:51:57 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 16:51:57 - Error connecting to the internet. 16:51:57 - Unable
to contact server..

Error - 08/05/2011 22:29:57 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 19:29:57 - Error connecting to the internet. 19:29:57 - Unable
to contact server..

Error - 11/05/2011 0:48:06 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 21:48:06 - Error connecting to the internet. 21:48:06 - Unable
to contact server..

[ System Events ]
Error - 16/05/2011 6:26:20 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
YOPIE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 16/05/2011 8:45:25 | Computer Name = Nyoo-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The
backup browser is stopping.

Error - 16/05/2011 20:30:38 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 17/05/2011 2:31:20 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 17/05/2011 2:40:22 | Computer Name = Nyoo-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The
backup browser is stopping.

Error - 17/05/2011 10:10:45 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 17/05/2011 11:38:41 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 18/05/2011 7:14:25 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
YOPIE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 18/05/2011 9:44:16 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
COMPUTER_1 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.

Error - 19/05/2011 3:29:21 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.


< End of report >
After I do the scan, I reinstall my firefox 3.6.3, does that mean I had to rescan again? I'm sorry if I post continuously.
Hi Blue_sky,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

After I do the scan, I reinstall my firefox 3.6.3, does that mean I had to rescan again?

Might have been better… but don't worry about it right now. Just carry on with the following instructions:

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Thank you for helping me. I forgot to tell you that I have uninstalled the iLivid and Searchqu from the control panel. I'm really sorry since I'm really clumsy.
I copied the code then pasted it in OTL. I did the wrong thing by using run scan first. Then I do the Run FIx. However, the only log I get isn't the OTL log, but this log:

All processes killed
========== PROCESSES ==========
========== OTL ==========
No active process named Program Files was found!
Prefs.js: "Web Search" removed from browser.search.defaultenginename
Prefs.js: "Web Search" removed from browser.search.order.1
Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully.
File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully.
File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64 folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\content folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\components folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON Stylus Photo R290 Series deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.
File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}\ not found.
File {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Nyoo's Family\Desktop\cmd.bat deleted successfully.
C:\Users\Nyoo's Family\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Nyoo's Family
->Temp folder emptied: 42286031 bytes
->Temporary Internet Files folder emptied: 33141907 bytes
->FireFox cache emptied: 57361523 bytes
->Flash cache emptied: 3235 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10195492 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 136,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05202011_220020

Files\Folders moved on Reboot…
C:\Users\Nyoo's Family\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
and this is the OTL log, for the last run scan before I run fix(I'm sorry about this, I'm so clumsy……. :( )

OTL logfile created on: 20/05/2011 21:57:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 68,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,78 Gb Free Space | 50,52% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS

Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Windows\VM30xSnap.exe (Vimicro)


========== Modules (SafeList) ==========

MOD - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Internet Download Manager\idmmkb.dll (Tonec Inc.)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfPCI) – C:\Windows\SysNative\drivers\VSTBS26.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysNative\drivers\vm30xx64.sys (Vimicro Corporation)
DRV - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysWOW64\drivers\vm30xx64.sys (Vimicro Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://id.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F9 F5 E8 31 0F CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.id/"
FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.http: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ssl_port: 8080

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/19 15:47:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/19 15:47:20 | 000,000,000 | —D | M]

[2011/05/15 23:30:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Extensions
[2011/05/16 17:12:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\extensions
[2011/05/19 21:53:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/10 08:41:26 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/05/15 23:30:25 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/05/08 09:50:10 | 000,000,000 | —D | M] (IDM CC) – C:\USERS\NYOO'S FAMILY\APPDATA\ROAMING\IDM\IDMMZCC3

O1 HOSTS File: ([2009/06/11 04:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [VM30xSnap] C:\Windows\VM30xSnap.exe (Vimicro)
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/19 15:47:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/19 14:58:35 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\index.php_files
[2011/05/18 22:05:21 | 012,521,992 | —- | C] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/05/15 23:27:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\PackageAware
[2011/05/14 14:12:07 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2011/05/14 14:12:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe Systems Shared
[2011/05/14 13:39:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
[2011/05/14 13:39:43 | 000,000,000 | —D | C] – C:\ProgramData\UDL
[2011/05/14 13:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Print CD
[2011/05/14 13:38:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON Print CD
[2011/05/14 13:37:04 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2011/05/14 13:37:04 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2011/05/14 13:37:04 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2011/05/14 13:37:04 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2011/05/14 13:37:04 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2011/05/14 13:36:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON
[2011/05/14 13:36:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2011/05/14 13:36:46 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2011/05/14 13:34:08 | 000,008,704 | —- | C] (SEIKO EPSON CORP.) – C:\Windows\SysNative\E_GCINST.DLL
[2011/05/14 13:34:05 | 000,129,536 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_ILMCKP.DLL
[2011/05/14 13:34:05 | 000,086,528 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_IBCBCKP.DLL
[2011/05/14 13:33:59 | 000,000,000 | —D | C] – C:\Program Files\EPSON
[2011/05/14 07:09:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/12 12:22:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple Computer
[2011/05/12 12:22:08 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Apple Computer
[2011/05/12 12:22:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/12 12:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/12 12:20:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/12 12:20:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\skypePM
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/05/10 08:40:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/05/10 08:27:52 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Skype
[2011/05/10 08:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/05/10 08:17:37 | 000,000,000 | —D | C] – C:\Lenovo Camera
[2011/05/10 08:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Camera
[2011/05/10 08:17:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Filter
[2011/05/10 08:17:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lenovo Camera
[2011/05/10 08:13:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vimicro USB PC Camera (ZC030x)
[2011/05/10 08:13:40 | 001,330,688 | —- | C] (Vimicro Corporation) – C:\Windows\SysNative\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 001,330,688 | R— | C] (Vimicro Corporation) – C:\Windows\SysWow64\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 000,249,856 | R— | C] (Vimicro) – C:\Windows\SysWow64\VM30xPRP.Ax
[2011/05/10 08:13:39 | 000,057,344 | R— | C] (Vimicro ) – C:\Windows\vm30xcap.exe
[2011/05/10 08:13:39 | 000,053,248 | R— | C] (Vimicro) – C:\Windows\VM30xSnap.exe
[2011/05/10 08:13:35 | 000,023,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drivers\usbcamd2.sys
[2011/05/10 08:13:34 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/10 08:13:34 | 000,348,160 | R— | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/10 08:12:57 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\InstallShield
[2011/05/09 10:10:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 6
[2011/05/09 09:59:13 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/05/09 09:21:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2011/05/09 09:21:07 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/05/09 09:20:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2011/05/09 09:20:58 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2011/05/09 09:19:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\PcSetup
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\DVDFab
[2011/05/08 22:17:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 6
[2011/05/08 13:20:43 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Games
[2011/05/08 12:35:03 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/08 11:41:05 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Macromedia
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Adobe
[2011/05/08 09:54:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\Downloads
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Internet Download Manager
[2011/05/08 09:28:51 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\LogMeIn Hamachi
[2011/05/08 09:28:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2011/05/08 09:24:35 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/08 07:00:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Mozilla
[2011/05/08 06:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/08 06:44:13 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/08 06:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2011/05/08 06:44:09 | 000,000,000 | —D | C] – C:\Program Files\TeraCopy
[2011/05/08 06:43:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ACDSee
[2011/05/08 06:43:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\ProgramData\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\ACD Systems
[2011/05/08 06:42:10 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/05/08 06:41:10 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/08 06:41:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/08 06:39:58 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Adobe
[2011/05/08 06:38:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Player Classic
[2011/05/08 06:37:55 | 000,839,680 | —- | C] (http://www.mp3dev.org/) – C:\Windows\SysWow64\lameACM.acm
[2011/05/08 06:37:55 | 000,287,744 | —- | C] (Kristal StudioDFileDescription) – C:\Windows\SysWow64\divxa32.acm
[2011/05/08 06:37:55 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\SysWow64\mp3fhg.acm
[2011/05/08 06:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/05/08 06:37:54 | 000,630,784 | —- | C] (On2.com) – C:\Windows\SysWow64\vp7vfw.dll
[2011/05/08 06:37:54 | 000,391,680 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\I263_32.drv
[2011/05/08 06:37:54 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/05/08 06:37:54 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\SysWow64\ac3acm.acm
[2011/05/08 06:37:54 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[2011/05/08 06:37:54 | 000,039,936 | —- | C] (Disappearing Inc.) – C:\Windows\SysWow64\huffyuv.dll
[2011/05/08 06:37:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\K-Lite Codec Pack
[2011/05/08 06:37:02 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\ashampoo
[2011/05/08 06:36:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ashampoo
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/05/08 06:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/08 06:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/08 06:29:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/08 06:28:50 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Help
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/05/08 06:28:42 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/05/08 06:28:26 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Searches
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/08 06:10:38 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/08 06:10:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Identities
[2011/05/08 06:10:04 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Contacts
[2011/05/08 06:10:00 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\VirtualStore
[2011/05/08 06:09:30 | 000,000,000 | –SD | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Videos
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Saved Games
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Pictures
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Music
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Links
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Favorites
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Downloads
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Desktop
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Temporary Internet Files
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Templates
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Start Menu
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\SendTo
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Recent
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\PrintHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\NetHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Videos
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Pictures
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Music
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Local Settings
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\History
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Cookies
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\AppData
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Temp
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Center Programs
[2011/05/08 06:09:03 | 000,000,000 | -HSD | C] – C:\Recovery
[2011/05/07 16:04:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/05/07 16:01:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/05/07 16:01:07 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2011/05/20 21:26:29 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 21:26:29 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 21:23:57 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/20 21:23:57 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/20 21:23:57 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/20 21:19:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/20 21:19:05 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 15:47:23 | 000,001,963 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 15:47:23 | 000,001,939 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/19 15:24:18 | 000,006,494 | —- | M] () – C:\Users\Nyoo's Family\Documents\bookmarks-2011-05-19.json
[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:18 | 000,297,791 | —- | M] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:13:42 | 012,521,992 | —- | M] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/14 20:02:17 | 001,660,864 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 20:01:47 | 001,648,820 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 20:01:09 | 001,743,628 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 19:59:55 | 001,647,664 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 19:57:51 | 000,002,058 | —- | M] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:24 | 030,476,905 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 13:33:48 | 000,000,025 | —- | M] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/12 12:09:50 | 000,000,016 | —- | M] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:44:51 | 000,000,056 | -H– | M] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:40:47 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:29:56 | 000,000,937 | —- | M] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/10 08:17:21 | 000,001,918 | —- | M] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/09 10:10:44 | 000,099,384 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/09 10:10:44 | 000,082,816 | —- | M] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/09 10:10:44 | 000,007,859 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/09 10:10:44 | 000,001,167 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/09 10:10:42 | 000,000,955 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | M] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/08 22:17:49 | 000,082,816 | —- | M] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 09:46:25 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 09:08:12 | 000,341,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/08 06:45:22 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:36:15 | 000,001,166 | —- | M] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiicdxx.dat

========== Files Created - No Company Name ==========

[2011/05/19 15:47:23 | 000,001,963 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 15:47:23 | 000,001,939 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/19 15:24:18 | 000,006,494 | —- | C] () – C:\Users\Nyoo's Family\Documents\bookmarks-2011-05-19.json
[2011/05/18 23:06:14 | 000,297,791 | —- | C] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/14 19:57:51 | 000,002,058 | —- | C] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:22 | 030,476,905 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:12:04 | 000,002,065 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS.lnk
[2011/05/14 14:12:04 | 000,002,058 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 14:09:12 | 001,660,864 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 14:09:00 | 001,648,820 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 14:07:52 | 001,743,628 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 14:07:28 | 001,647,664 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 13:37:04 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/05/14 13:37:04 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2011/05/14 13:37:04 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2011/05/14 13:37:04 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2011/05/14 13:37:04 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2011/05/14 13:37:04 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2011/05/14 13:37:04 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2011/05/14 13:37:04 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2011/05/14 13:37:04 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2011/05/14 13:37:04 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2011/05/14 13:37:04 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2011/05/14 13:37:04 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2011/05/14 13:37:04 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2011/05/14 13:37:04 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2011/05/14 13:37:04 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2011/05/14 13:37:04 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2011/05/14 13:37:04 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2011/05/14 13:37:04 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2011/05/14 13:37:04 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/05/14 13:37:04 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/05/14 13:37:04 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2011/05/14 13:37:04 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2011/05/14 13:37:04 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/05/14 13:37:04 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2011/05/14 13:33:48 | 000,000,025 | —- | C] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/14 07:09:08 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/12 12:20:37 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/10 08:44:51 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:27:21 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:17:42 | 000,000,016 | —- | C] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:17:21 | 000,001,918 | —- | C] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/10 08:13:39 | 000,049,152 | R— | C] () – C:\Windows\amcap.exe
[2011/05/10 08:13:36 | 000,138,752 | —- | C] () – C:\Windows\VM303Uninst64.exe
[2011/05/10 08:13:36 | 000,073,728 | —- | C] () – C:\Windows\VMInstNT.exe
[2011/05/10 08:13:36 | 000,069,632 | —- | C] () – C:\Windows\VMInst64.exe
[2011/05/10 08:13:35 | 000,040,960 | —- | C] () – C:\Windows\VM303UninstNT.exe
[2011/05/09 10:10:42 | 000,000,955 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | C] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/09 09:08:52 | 000,000,937 | —- | C] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/08 22:17:49 | 000,099,384 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/08 22:17:49 | 000,007,859 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/08 22:17:49 | 000,001,167 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/08 09:46:25 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 06:45:22 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:37:55 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/05/08 06:37:55 | 000,000,414 | —- | C] () – C:\Windows\SysWow64\lame_acm.xml
[2011/05/08 06:37:55 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/05/08 06:37:54 | 002,600,448 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/05/08 06:37:54 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/08 06:37:54 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/08 06:37:54 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/05/08 06:36:15 | 000,001,166 | —- | C] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/08 06:10:55 | 000,001,409 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/08 06:10:41 | 000,001,443 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/08 06:09:30 | 000,000,290 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/08 06:09:30 | 000,000,272 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/07 16:04:59 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/07 16:04:48 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2011/05/07 16:01:07 | 1608,179,712 | -HS- | C] () – C:\hiberfil.sys
[2009/07/14 12:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 09:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 09:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 07:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 06:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 04:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 04:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2002/03/22 05:39:02 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\UNACEV2.DLL

========== Custom Scans ==========


< :Processes >

< >

< :OTL >

< PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >

< FF - prefs.js..browser.search.defaultenginename: "Web Search" >

< FF - prefs.js..browser.search.order.1: "Web Search" >

< FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;=" >

< O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >

< O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >

< O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >

< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD) >

< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >

< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD) >

< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >

< [2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar >
Invalid Switch: 15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar


< O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. >

< O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. >

< O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found >

< O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found >

< O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found >

< O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found >
Invalid Switch: pagefile) - File not found


< O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found >
Invalid Switch: pagefile) - File not found


< O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. >

< O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. >

< >

< :Files >

< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.

< >

< :Commands >

< [purity] >

< [emptytemp] >

< [start explorer] >

< [Reboot] >

< End of report >
Blue_sky,

You did fine. The "fix" log you provided is correct. :thumbup:

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
okay, I have do it, this is the log. for now there's no searchqu's effect which I know that is still going, the system is better now. ComboFix 11-05-19.02 - Nyoo's Family 21/05/2011 13:57:42.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.62.1033.18.2045.1311 [GMT 7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Nyoo's Family\AppData\Roaming\inst.exe c:\users\Nyoo's Family\AppData\Roaming\pcouffin.sys . . ((((((((((((((((((((((((( Files Created from 2011-04-21 to 2011-05-21 ))))))))))))))))))))))))))))))) . . 2011-05-21 07:01 . 2011-05-21 07:01 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-20 15:00 . 2011-05-20 15:00 ——– d—–w- C:\_OTL 2011-05-14 07:12 . 2011-05-14 07:12 ——– d—–w- c:\programdata\Macrovision 2011-05-14 07:12 . 2011-05-14 07:12 ——– d—–w- c:\program files (x86)\Common Files\Adobe Systems Shared 2011-05-14 06:39 . 2011-05-14 06:39 ——– d—–w- c:\programdata\UDL 2011-05-14 06:38 . 2011-05-14 06:38 ——– d—–w- c:\program files (x86)\EPSON Print CD 2011-05-14 06:37 . 2006-10-31 07:10 71840 —-a-w- c:\windows\SysWow64\EPPicMgr.dll 2011-05-14 06:37 . 2006-10-31 07:10 120992 —-a-w- c:\windows\SysWow64\EpPicPrt.dll 2011-05-14 06:37 . 2006-10-20 07:10 80024 —-a-w- c:\windows\SysWow64\PICSDK.dll 2011-05-14 06:37 . 2006-10-20 07:10 501912 —-a-w- c:\windows\SysWow64\PICSDK2.dll 2011-05-14 06:37 . 2006-10-20 07:10 108704 —-a-w- c:\windows\SysWow64\PICEntry.dll 2011-05-14 06:36 . 2011-05-14 06:38 ——– d—–w- c:\program files (x86)\EPSON 2011-05-14 06:36 . 2011-05-14 06:36 ——– d—–w- c:\programdata\EPSON 2011-05-14 06:34 . 2005-02-02 12:05 8704 —-a-w- c:\windows\system32\E_GCINST.DLL 2011-05-14 06:34 . 2006-12-08 02:04 129536 —-a-w- c:\windows\system32\E_ILMCKP.DLL 2011-05-14 06:34 . 2006-04-19 02:00 86528 —-a-w- c:\windows\system32\E_IBCBCKP.DLL 2011-05-14 06:33 . 2011-05-14 06:33 ——– d—–w- c:\program files\EPSON 2011-05-14 00:09 . 2011-05-14 07:11 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-05-12 05:23 . 2011-05-12 05:23 ——– d—–w- c:\programdata\Trymedia 2011-05-12 05:21 . 2011-05-12 05:22 ——– d—–w- c:\program files (x86)\iTunes 2011-05-12 05:21 . 2011-05-12 05:21 ——– d—–w- c:\program files (x86)\iPod 2011-05-12 05:21 . 2011-05-12 05:21 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-05-12 05:20 . 2011-05-12 05:21 ——– d—–w- c:\programdata\Apple Computer 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\QuickTime 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\programdata\Apple 2011-05-10 01:44 . 2011-05-20 23:09 ——– d—–w- c:\programdata\Skype Extras 2011-05-10 01:40 . 2011-05-10 01:40 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-05-10 01:40 . 2011-05-10 01:41 ——– d—–r- c:\program files (x86)\Skype 2011-05-10 01:26 . 2011-05-10 01:40 ——– d—–w- c:\programdata\Skype 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- C:\Lenovo Camera 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- c:\program files (x86)\Filter 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- c:\program files (x86)\Lenovo Camera 2011-05-09 02:21 . 2011-05-09 02:21 ——– d—–w- c:\programdata\CyberLink 2011-05-09 02:20 . 2011-05-09 02:21 ——– d—–w- c:\program files (x86)\CyberLink 2011-05-09 02:20 . 2011-05-14 07:10 ——– d–h–w- c:\program files (x86)\InstallShield Installation Information 2011-05-09 02:19 . 2011-05-14 06:40 ——– d—–w- c:\program files (x86)\Common Files\InstallShield 2011-05-08 15:17 . 2011-05-08 15:17 82816 —-a-w- c:\windows\system32\drivers\pcouffin.sys 2011-05-08 15:17 . 2011-05-09 03:10 ——– d—–w- c:\program files (x86)\DVDFab 6 2011-05-08 02:54 . 2011-05-08 02:54 ——– d—–w- c:\windows\SysWow64\Macromed 2011-05-08 02:50 . 2011-05-08 02:50 ——– d—–w- c:\program files (x86)\Internet Download Manager 2011-05-08 02:35 . 2011-04-18 16:15 8802128 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2D781BB-B724-4882-A167-69315F72EC5A}\mpengine.dll 2011-05-08 02:35 . 2011-02-03 01:11 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-08 02:28 . 2011-05-08 02:28 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2011-05-08 02:24 . 2009-03-19 00:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2011-05-08 00:00 . 2011-05-07 23:09 ——– d—–w- c:\windows\Panther 2011-05-07 23:44 . 2011-05-07 23:44 ——– d—–w- c:\program files\TeraCopy 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\programdata\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\program files (x86)\Common Files\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\program files (x86)\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\windows\Downloaded Installations 2011-05-07 23:36 . 2011-05-07 23:36 ——– d—–w- c:\programdata\ashampoo 2011-05-07 23:36 . 2011-05-07 23:36 ——– d—–w- c:\program files (x86)\Ashampoo 2011-05-07 23:30 . 2011-05-07 23:33 ——– d—–w- c:\program files (x86)\Microsoft Works 2011-05-07 23:30 . 2011-05-07 23:30 ——– d—–w- c:\windows\PCHEALTH 2011-05-07 23:30 . 2011-05-07 23:30 ——– d—–w- c:\program files (x86)\Microsoft.NET 2011-05-07 23:28 . 2011-05-07 23:34 ——– d—–w- c:\programdata\Microsoft Help 2011-05-07 23:28 . 2011-05-18 15:28 ——– d-sh–w- c:\windows\Installer 2011-05-07 23:28 . 2011-05-07 23:28 ——– d—–r- C:\MSOCache 2011-05-07 23:09 . 2011-05-07 23:10 ——– d—–w- c:\users\Nyoo's Family 2011-05-07 23:09 . 2011-05-07 23:09 ——– d—–w- C:\Recovery 2011-05-07 09:03 . 2011-05-07 09:03 0 —-a-w- c:\windows\ativpsrm.bin . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2010-01-25 3179952] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-04-19 15146376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "VM30xSnap"="VM30xSnap.exe Vimicro USB PC Camera (ZC030x)" [X] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2009-05-27 413696] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2009-07-13 292128] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-5-14 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1823112] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 SrvHsfPCI;SrvHsfPCI;c:\windows\system32\DRIVERS\VSTBS26.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] S3 VM30xx64;Vimicro USB PC Camera (ZC0301);c:\windows\system32\Drivers\vm30xx64.sys [2007-02-15 1330688] . . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.searchqu.com/406 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files (x86)\Internet Download Manager\IEGetVL.htm IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.id/ FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: IDM CC: [removed] - c:\users\Nyoo's Family\AppData\Roaming\IDM\idmmzcc3 . - - - - ORPHANS REMOVED - - - - . AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows iLivid Toolbar\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar0] "BarID"=dword:0000e81b "Bars"=dword:00000003 "Bar#0"=dword:00000000 "Bar#1"=dword:0000e800 "Bar#2"=dword:00000000 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar1] "BarID"=dword:0000e81c "Bars"=dword:00000004 "Bar#0"=dword:00000000 "Bar#1"=dword:0000e807 "Bar#2"=dword:0000e806 "Bar#3"=dword:00000000 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar2] "BarID"=dword:0000e800 "XPos"=dword:fffffffe "YPos"=dword:fffffffe "Docking"=dword:00000001 "MRUDockID"=dword:00000000 "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:fffffffe "MRUDockRightPos"=dword:000001f5 "MRUDockBottomPos"=dword:00000036 "MRUFloatStyle"=dword:00002000 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar3] "BarID"=dword:0000e806 "XPos"=dword:fffffffe "YPos"=dword:00000141 "Docking"=dword:00000001 "MRUDockID"=dword:0000e81c "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:00000141 "MRUDockRightPos"=dword:000000c6 "MRUDockBottomPos"=dword:00000287 "MRUFloatStyle"=dword:00002004 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar4] "BarID"=dword:0000e807 "XPos"=dword:fffffffe "YPos"=dword:fffffffe "Docking"=dword:00000001 "MRUDockID"=dword:00000000 "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:fffffffe "MRUDockRightPos"=dword:000000c6 "MRUDockBottomPos"=dword:00000143 "MRUFloatStyle"=dword:00002004 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Summary] "Bars"=dword:00000005 "ScreenCX"=dword:00000400 "ScreenCY"=dword:00000300 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Settings] "FirstRun"=dword:00000000 "xScreen"=dword:00000400 "yScreen"=dword:000002c4 "lastDir"="c:\\WINNT\\" "floats"="1.000000 0.500000 0.500000 120 120" "skin"="ISR_10Moons.dll" . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\WNDSTATUS] "FLAG"=dword:00000000 "SHOWCMD"=dword:00000001 "LEFT"=dword:fffffffc "TOP"=dword:fffffffc "RIGHT"=dword:00000404 "BOTTOM"=dword:000002e2 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-21 14:02:39 ComboFix-quarantined-files.txt 2011-05-21 07:02 . Pre-Run: 20.859.432.960 bytes free Post-Run: 20.611.792.896 bytes free . - - End Of File - - 297D9950AD8AE6A13B60CAEAFE83C321
Blue_sky,

One little entry still hanging on…

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uStart Page = hxxp://www.searchqu.com/406
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
here's the log: ComboFix 11-05-19.02 - Nyoo's Family 22/05/2011 11:46:49.2.2 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.62.1033.18.2045.1305 [GMT 7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Nyoo's Family\Desktop\CFScript.txt SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-04-22 to 2011-05-22 ))))))))))))))))))))))))))))))) . . 2011-05-22 04:50 . 2011-05-22 04:50 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-05-20 15:00 . 2011-05-20 15:00 ——– d—–w- C:\_OTL 2011-05-14 07:12 . 2011-05-14 07:12 ——– d—–w- c:\programdata\Macrovision 2011-05-14 07:12 . 2011-05-14 07:12 ——– d—–w- c:\program files (x86)\Common Files\Adobe Systems Shared 2011-05-14 06:39 . 2011-05-14 06:39 ——– d—–w- c:\programdata\UDL 2011-05-14 06:38 . 2011-05-14 06:38 ——– d—–w- c:\program files (x86)\EPSON Print CD 2011-05-14 06:37 . 2006-10-31 07:10 71840 —-a-w- c:\windows\SysWow64\EPPicMgr.dll 2011-05-14 06:37 . 2006-10-31 07:10 120992 —-a-w- c:\windows\SysWow64\EpPicPrt.dll 2011-05-14 06:37 . 2006-10-20 07:10 80024 —-a-w- c:\windows\SysWow64\PICSDK.dll 2011-05-14 06:37 . 2006-10-20 07:10 501912 —-a-w- c:\windows\SysWow64\PICSDK2.dll 2011-05-14 06:37 . 2006-10-20 07:10 108704 —-a-w- c:\windows\SysWow64\PICEntry.dll 2011-05-14 06:36 . 2011-05-14 06:38 ——– d—–w- c:\program files (x86)\EPSON 2011-05-14 06:36 . 2011-05-14 06:36 ——– d—–w- c:\programdata\EPSON 2011-05-14 06:34 . 2005-02-02 12:05 8704 —-a-w- c:\windows\system32\E_GCINST.DLL 2011-05-14 06:34 . 2006-12-08 02:04 129536 —-a-w- c:\windows\system32\E_ILMCKP.DLL 2011-05-14 06:34 . 2006-04-19 02:00 86528 —-a-w- c:\windows\system32\E_IBCBCKP.DLL 2011-05-14 06:33 . 2011-05-14 06:33 ——– d—–w- c:\program files\EPSON 2011-05-14 00:09 . 2011-05-14 07:11 ——– d—–w- c:\program files (x86)\Common Files\Adobe 2011-05-12 05:23 . 2011-05-12 05:23 ——– d—–w- c:\programdata\Trymedia 2011-05-12 05:21 . 2011-05-12 05:22 ——– d—–w- c:\program files (x86)\iTunes 2011-05-12 05:21 . 2011-05-12 05:21 ——– d—–w- c:\program files (x86)\iPod 2011-05-12 05:21 . 2011-05-12 05:21 ——– d—–w- c:\program files (x86)\Common Files\Apple 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\Bonjour 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-05-12 05:20 . 2011-05-12 05:20 143360 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-05-12 05:20 . 2011-05-12 05:21 ——– d—–w- c:\programdata\Apple Computer 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\QuickTime 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\program files (x86)\Apple Software Update 2011-05-12 05:20 . 2011-05-12 05:20 ——– d—–w- c:\programdata\Apple 2011-05-10 01:44 . 2011-05-20 23:09 ——– d—–w- c:\programdata\Skype Extras 2011-05-10 01:40 . 2011-05-10 01:40 ——– d—–w- c:\program files (x86)\Common Files\Skype 2011-05-10 01:40 . 2011-05-10 01:41 ——– d—–r- c:\program files (x86)\Skype 2011-05-10 01:26 . 2011-05-10 01:40 ——– d—–w- c:\programdata\Skype 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- C:\Lenovo Camera 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- c:\program files (x86)\Filter 2011-05-10 01:17 . 2011-05-10 01:17 ——– d—–w- c:\program files (x86)\Lenovo Camera 2011-05-09 02:21 . 2011-05-09 02:21 ——– d—–w- c:\programdata\CyberLink 2011-05-09 02:20 . 2011-05-09 02:21 ——– d—–w- c:\program files (x86)\CyberLink 2011-05-09 02:20 . 2011-05-14 07:10 ——– d–h–w- c:\program files (x86)\InstallShield Installation Information 2011-05-09 02:19 . 2011-05-14 06:40 ——– d—–w- c:\program files (x86)\Common Files\InstallShield 2011-05-08 15:17 . 2011-05-08 15:17 82816 —-a-w- c:\windows\system32\drivers\pcouffin.sys 2011-05-08 15:17 . 2011-05-09 03:10 ——– d—–w- c:\program files (x86)\DVDFab 6 2011-05-08 02:54 . 2011-05-08 02:54 ——– d—–w- c:\windows\SysWow64\Macromed 2011-05-08 02:50 . 2011-05-08 02:50 ——– d—–w- c:\program files (x86)\Internet Download Manager 2011-05-08 02:35 . 2011-04-18 16:15 8802128 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E2D781BB-B724-4882-A167-69315F72EC5A}\mpengine.dll 2011-05-08 02:35 . 2011-02-03 01:11 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-08 02:28 . 2011-05-08 02:28 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2011-05-08 02:24 . 2009-03-19 00:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2011-05-08 00:00 . 2011-05-07 23:09 ——– d—–w- c:\windows\Panther 2011-05-07 23:44 . 2011-05-07 23:44 ——– d—–w- c:\program files\TeraCopy 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\programdata\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\program files (x86)\Common Files\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\program files (x86)\ACD Systems 2011-05-07 23:42 . 2011-05-07 23:42 ——– d—–w- c:\windows\Downloaded Installations 2011-05-07 23:36 . 2011-05-07 23:36 ——– d—–w- c:\programdata\ashampoo 2011-05-07 23:36 . 2011-05-07 23:36 ——– d—–w- c:\program files (x86)\Ashampoo 2011-05-07 23:30 . 2011-05-07 23:33 ——– d—–w- c:\program files (x86)\Microsoft Works 2011-05-07 23:30 . 2011-05-07 23:30 ——– d—–w- c:\windows\PCHEALTH 2011-05-07 23:30 . 2011-05-07 23:30 ——– d—–w- c:\program files (x86)\Microsoft.NET 2011-05-07 23:28 . 2011-05-07 23:34 ——– d—–w- c:\programdata\Microsoft Help 2011-05-07 23:28 . 2011-05-18 15:28 ——– d-sh–w- c:\windows\Installer 2011-05-07 23:28 . 2011-05-07 23:28 ——– d—–r- C:\MSOCache 2011-05-07 23:09 . 2011-05-07 23:10 ——– d—–w- c:\users\Nyoo's Family 2011-05-07 23:09 . 2011-05-07 23:09 ——– d—–w- C:\Recovery 2011-05-07 09:03 . 2011-05-07 09:03 0 —-a-w- c:\windows\ativpsrm.bin . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((( SnapShot@2011-05-21_07.01.22 ))))))))))))))))))))))))))))))))))))))))) . + 2011-05-08 02:11 . 2011-05-22 04:37 18716 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-05-21 06:48 25082 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-05-22 04:37 25082 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-08 02:17 . 2011-05-22 04:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-08 02:17 . 2011-05-21 06:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-05-08 02:17 . 2011-05-22 04:38 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-05-08 02:17 . 2011-05-21 06:49 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-05-08 02:17 . 2011-05-21 06:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-05-08 02:17 . 2011-05-22 04:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-05-07 23:39 . 2011-05-22 04:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-07 23:39 . 2011-05-21 06:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-07 23:39 . 2011-05-21 06:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-05-07 23:39 . 2011-05-22 04:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-05-07 23:16 . 2011-05-22 04:37 4512 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1036888637-3177725529-315093088-1000_UserData.bin - 2011-05-07 23:16 . 2011-05-21 06:48 4512 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1036888637-3177725529-315093088-1000_UserData.bin + 2011-05-22 04:35 . 2011-05-22 04:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-05-21 06:47 . 2011-05-21 06:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-05-21 06:47 . 2011-05-21 06:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-05-22 04:35 . 2011-05-22 04:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 02:36 . 2011-05-21 06:52 606992 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-05-22 04:40 606992 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-05-22 04:40 103370 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-05-21 06:52 103370 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-05-19 09:12 328052 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-05-22 01:08 328052 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-05-18 16:57 . 2011-05-22 01:09 328052 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1036888637-3177725529-315093088-1000-12288.dat - 2011-05-18 16:57 . 2011-05-19 09:12 328052 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1036888637-3177725529-315093088-1000-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2010-01-25 3179952] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-04-19 15146376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "VM30xSnap"="VM30xSnap.exe Vimicro USB PC Camera (ZC030x)" [X] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2009-05-27 413696] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2009-07-13 292128] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-5-14 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1823112] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 SrvHsfPCI;SrvHsfPCI;c:\windows\system32\DRIVERS\VSTBS26.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] S3 VM30xx64;Vimicro USB PC Camera (ZC0301);c:\windows\system32\Drivers\vm30xx64.sys [2007-02-15 1330688] . . . ——— x86-64 ———– . . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files (x86)\Internet Download Manager\IEGetVL.htm IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.id/ . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar0] "BarID"=dword:0000e81b "Bars"=dword:00000003 "Bar#0"=dword:00000000 "Bar#1"=dword:0000e800 "Bar#2"=dword:00000000 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar1] "BarID"=dword:0000e81c "Bars"=dword:00000004 "Bar#0"=dword:00000000 "Bar#1"=dword:0000e807 "Bar#2"=dword:0000e806 "Bar#3"=dword:00000000 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar2] "BarID"=dword:0000e800 "XPos"=dword:fffffffe "YPos"=dword:fffffffe "Docking"=dword:00000001 "MRUDockID"=dword:00000000 "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:fffffffe "MRUDockRightPos"=dword:000001f5 "MRUDockBottomPos"=dword:00000036 "MRUFloatStyle"=dword:00002000 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar3] "BarID"=dword:0000e806 "XPos"=dword:fffffffe "YPos"=dword:00000141 "Docking"=dword:00000001 "MRUDockID"=dword:0000e81c "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:00000141 "MRUDockRightPos"=dword:000000c6 "MRUDockBottomPos"=dword:00000287 "MRUFloatStyle"=dword:00002004 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Bar4] "BarID"=dword:0000e807 "XPos"=dword:fffffffe "YPos"=dword:fffffffe "Docking"=dword:00000001 "MRUDockID"=dword:00000000 "MRUDockLeftPos"=dword:fffffffe "MRUDockTopPos"=dword:fffffffe "MRUDockRightPos"=dword:000000c6 "MRUDockBottomPos"=dword:00000143 "MRUFloatStyle"=dword:00002004 "MRUFloatXPos"=dword:80000000 "MRUFloatYPos"=dword:cdcdcdcd . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Bars\Settings-Summary] "Bars"=dword:00000005 "ScreenCX"=dword:00000400 "ScreenCY"=dword:00000300 . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\Settings] "FirstRun"=dword:00000000 "xScreen"=dword:00000400 "yScreen"=dword:000002c4 "lastDir"="c:\\WINNT\\" "floats"="1.000000 0.500000 0.500000 120 120" "skin"="ISR_10Moons.dll" . [HKEY_USERS\S-1-5-21-1036888637-3177725529-315093088-1000\Software\10Moons\þV * *Gr * *Om * *ȉ * *hV *\WNDSTATUS] "FLAG"=dword:00000000 "SHOWCMD"=dword:00000001 "LEFT"=dword:fffffffc "TOP"=dword:fffffffc "RIGHT"=dword:00000404 "BOTTOM"=dword:000002e2 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-05-22 11:51:33 ComboFix-quarantined-files.txt 2011-05-22 04:51 ComboFix2.txt 2011-05-21 07:02 . Pre-Run: 20.496.060.416 bytes free Post-Run: 20.453.793.792 bytes free . - - End Of File - - 55780E40312B240A1B9BCC745CA493BD
Blue_sky,

Looking good.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Also let me know how things seem to be running.
ummm, I can;t find this the button that says ESET Online Scanner, but there's the "Run ESET Online Scanner" button. Click that one?
Blue_sky,

That is interesting because I have tried it in Internet Explorer, Chrome, and Firefox and all give me the same thing:

STEP ONE: Run free on-demand scan
ESET Online Scanner a fast and and free tool that detects and removes threats on your PC. Utilizing only your browser, it scans your computer with ESET's award-winning ThreatSense engine.
[external image: Posted Image]


Maybe the page reads differently when accessed from different countries, but based upon what you are telling me… clicking on "Run ESET Online Scanner" would seem like the appropriate thing to do.
here's the log. It takes quite the time since my internet connection is a bit slow. I never knew I had windows Defender installed i my computer, but deactivated it before the scan. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=f588d48c4a56f94bad0919472ca94470 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-05-23 07:30:26 # local_time=2011-05-23 02:30:26 (+0700, SE Asia Standard Time) # country="Indonesia" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=5893 16776573 100 94 476619 57763782 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=115684 # found=0 # cleaned=0 # scan_time=1894

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI