Searchqu Malware
13 min read
OTL logfile created on: 19/05/2011 15:05:13 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,84 Gb Free Space | 50,70% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS
Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Windows\VM30xSnap.exe (Vimicro)
========== Modules (SafeList) ==========
MOD - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Internet Download Manager\idmmkb.dll (Tonec Inc.)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfPCI) – C:\Windows\SysNative\drivers\VSTBS26.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysNative\drivers\vm30xx64.sys (Vimicro Corporation)
DRV - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysWOW64\drivers\vm30xx64.sys (Vimicro Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://id.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F9 F5 E8 31 0F CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.id/"
FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.http: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/18 22:34:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/18 22:34:07 | 000,000,000 | —D | M]
[2011/05/15 23:30:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Extensions
[2011/05/16 17:12:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\extensions
[2011/05/18 22:34:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/10 08:41:26 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) –
[2011/04/14 23:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 15:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2009/06/11 04:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [VM30xSnap] C:\Windows\VM30xSnap.exe (Vimicro)
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: vidc.MP42 - MPG4c32.dll File not found
Drivers32: vidc.MP43 - MPG4c32.dll File not found
Drivers32: vidc.MPG4 - MPG4c32.dll File not found
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/05/19 14:58:35 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\index.php_files
[2011/05/18 22:05:21 | 012,521,992 | —- | C] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/05/15 23:27:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\PackageAware
[2011/05/14 14:12:07 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2011/05/14 14:12:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe Systems Shared
[2011/05/14 13:39:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
[2011/05/14 13:39:43 | 000,000,000 | —D | C] – C:\ProgramData\UDL
[2011/05/14 13:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Print CD
[2011/05/14 13:38:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON Print CD
[2011/05/14 13:37:04 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2011/05/14 13:37:04 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2011/05/14 13:37:04 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2011/05/14 13:37:04 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2011/05/14 13:37:04 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2011/05/14 13:36:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON
[2011/05/14 13:36:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2011/05/14 13:36:46 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2011/05/14 13:34:08 | 000,008,704 | —- | C] (SEIKO EPSON CORP.) – C:\Windows\SysNative\E_GCINST.DLL
[2011/05/14 13:34:05 | 000,129,536 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_ILMCKP.DLL
[2011/05/14 13:34:05 | 000,086,528 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_IBCBCKP.DLL
[2011/05/14 13:33:59 | 000,000,000 | —D | C] – C:\Program Files\EPSON
[2011/05/14 07:09:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/12 12:22:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple Computer
[2011/05/12 12:22:08 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Apple Computer
[2011/05/12 12:22:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/12 12:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/12 12:20:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/12 12:20:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\skypePM
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/05/10 08:40:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/05/10 08:27:52 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Skype
[2011/05/10 08:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/05/10 08:17:37 | 000,000,000 | —D | C] – C:\Lenovo Camera
[2011/05/10 08:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Camera
[2011/05/10 08:17:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Filter
[2011/05/10 08:17:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lenovo Camera
[2011/05/10 08:13:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vimicro USB PC Camera (ZC030x)
[2011/05/10 08:13:40 | 001,330,688 | —- | C] (Vimicro Corporation) – C:\Windows\SysNative\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 001,330,688 | R— | C] (Vimicro Corporation) – C:\Windows\SysWow64\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 000,249,856 | R— | C] (Vimicro) – C:\Windows\SysWow64\VM30xPRP.Ax
[2011/05/10 08:13:39 | 000,057,344 | R— | C] (Vimicro ) – C:\Windows\vm30xcap.exe
[2011/05/10 08:13:39 | 000,053,248 | R— | C] (Vimicro) – C:\Windows\VM30xSnap.exe
[2011/05/10 08:13:35 | 000,023,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drivers\usbcamd2.sys
[2011/05/10 08:13:34 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/10 08:13:34 | 000,348,160 | R— | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/10 08:12:57 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\InstallShield
[2011/05/09 10:10:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 6
[2011/05/09 09:59:13 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/05/09 09:21:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2011/05/09 09:21:07 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/05/09 09:20:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2011/05/09 09:20:58 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2011/05/09 09:19:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\PcSetup
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\DVDFab
[2011/05/08 22:17:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 6
[2011/05/08 13:20:43 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Games
[2011/05/08 12:35:03 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/08 11:41:05 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Macromedia
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Adobe
[2011/05/08 09:54:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\Downloads
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Internet Download Manager
[2011/05/08 09:28:51 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\LogMeIn Hamachi
[2011/05/08 09:28:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2011/05/08 09:24:35 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/08 07:00:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Mozilla
[2011/05/08 06:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/08 06:44:13 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/08 06:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2011/05/08 06:44:09 | 000,000,000 | —D | C] – C:\Program Files\TeraCopy
[2011/05/08 06:43:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ACDSee
[2011/05/08 06:43:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\ProgramData\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\ACD Systems
[2011/05/08 06:42:10 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/05/08 06:41:10 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/08 06:41:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/08 06:39:58 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Adobe
[2011/05/08 06:38:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Player Classic
[2011/05/08 06:37:55 | 000,839,680 | —- | C] (http://www.mp3dev.org/) – C:\Windows\SysWow64\lameACM.acm
[2011/05/08 06:37:55 | 000,287,744 | —- | C] (Kristal StudioDFileDescription) – C:\Windows\SysWow64\divxa32.acm
[2011/05/08 06:37:55 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\SysWow64\mp3fhg.acm
[2011/05/08 06:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/05/08 06:37:54 | 000,630,784 | —- | C] (On2.com) – C:\Windows\SysWow64\vp7vfw.dll
[2011/05/08 06:37:54 | 000,391,680 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\I263_32.drv
[2011/05/08 06:37:54 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/05/08 06:37:54 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\SysWow64\ac3acm.acm
[2011/05/08 06:37:54 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[2011/05/08 06:37:54 | 000,039,936 | —- | C] (Disappearing Inc.) – C:\Windows\SysWow64\huffyuv.dll
[2011/05/08 06:37:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\K-Lite Codec Pack
[2011/05/08 06:37:02 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\ashampoo
[2011/05/08 06:36:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ashampoo
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/05/08 06:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/08 06:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/08 06:29:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/08 06:28:50 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Help
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/05/08 06:28:42 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/05/08 06:28:26 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Searches
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/08 06:10:38 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/08 06:10:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Identities
[2011/05/08 06:10:04 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Contacts
[2011/05/08 06:10:00 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\VirtualStore
[2011/05/08 06:09:30 | 000,000,000 | –SD | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Videos
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Saved Games
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Pictures
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Music
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Links
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Favorites
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Downloads
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Desktop
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Temporary Internet Files
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Templates
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Start Menu
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\SendTo
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Recent
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\PrintHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\NetHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Videos
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Pictures
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Music
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Local Settings
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\History
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Cookies
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\AppData
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Temp
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Center Programs
[2011/05/08 06:09:03 | 000,000,000 | -HSD | C] – C:\Recovery
[2011/05/07 16:04:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/05/07 16:01:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/05/07 16:01:07 | 000,000,000 | -HSD | C] – C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/19 14:33:25 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 14:33:25 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 14:30:53 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/19 14:30:53 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/19 14:30:53 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/19 14:26:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/19 14:26:09 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/18 23:06:18 | 000,297,791 | —- | M] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:34:22 | 000,002,052 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 22:34:08 | 000,001,138 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/18 22:13:42 | 012,521,992 | —- | M] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/14 20:02:17 | 001,660,864 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 20:01:47 | 001,648,820 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 20:01:09 | 001,743,628 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 19:59:55 | 001,647,664 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 19:57:51 | 000,002,058 | —- | M] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:24 | 030,476,905 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 13:33:48 | 000,000,025 | —- | M] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/12 12:09:50 | 000,000,016 | —- | M] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:44:51 | 000,000,056 | -H– | M] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:40:47 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:29:56 | 000,000,937 | —- | M] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/10 08:17:21 | 000,001,918 | —- | M] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/09 10:10:44 | 000,099,384 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/09 10:10:44 | 000,082,816 | —- | M] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/09 10:10:44 | 000,007,859 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/09 10:10:44 | 000,001,167 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/09 10:10:42 | 000,000,955 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | M] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/08 22:17:49 | 000,082,816 | —- | M] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 09:46:25 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 09:08:12 | 000,341,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/08 06:45:22 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:36:15 | 000,001,166 | —- | M] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiicdxx.dat
========== Files Created - No Company Name ==========
[2011/05/18 23:06:14 | 000,297,791 | —- | C] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:34:08 | 000,001,150 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/18 22:29:28 | 000,002,052 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/18 22:29:28 | 000,001,138 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/14 19:57:51 | 000,002,058 | —- | C] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:22 | 030,476,905 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:12:04 | 000,002,065 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS.lnk
[2011/05/14 14:12:04 | 000,002,058 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 14:09:12 | 001,660,864 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 14:09:00 | 001,648,820 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 14:07:52 | 001,743,628 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 14:07:28 | 001,647,664 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 13:37:04 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/05/14 13:37:04 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2011/05/14 13:37:04 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2011/05/14 13:37:04 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2011/05/14 13:37:04 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2011/05/14 13:37:04 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2011/05/14 13:37:04 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2011/05/14 13:37:04 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2011/05/14 13:37:04 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2011/05/14 13:37:04 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2011/05/14 13:37:04 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2011/05/14 13:37:04 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2011/05/14 13:37:04 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2011/05/14 13:37:04 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2011/05/14 13:37:04 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2011/05/14 13:37:04 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2011/05/14 13:37:04 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2011/05/14 13:37:04 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2011/05/14 13:37:04 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/05/14 13:37:04 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/05/14 13:37:04 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2011/05/14 13:37:04 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2011/05/14 13:37:04 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/05/14 13:37:04 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2011/05/14 13:33:48 | 000,000,025 | —- | C] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/14 07:09:08 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/12 12:20:37 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/10 08:44:51 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:27:21 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:17:42 | 000,000,016 | —- | C] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:17:21 | 000,001,918 | —- | C] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/10 08:13:39 | 000,049,152 | R— | C] () – C:\Windows\amcap.exe
[2011/05/10 08:13:36 | 000,138,752 | —- | C] () – C:\Windows\VM303Uninst64.exe
[2011/05/10 08:13:36 | 000,073,728 | —- | C] () – C:\Windows\VMInstNT.exe
[2011/05/10 08:13:36 | 000,069,632 | —- | C] () – C:\Windows\VMInst64.exe
[2011/05/10 08:13:35 | 000,040,960 | —- | C] () – C:\Windows\VM303UninstNT.exe
[2011/05/09 10:10:42 | 000,000,955 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | C] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/09 09:08:52 | 000,000,937 | —- | C] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/08 22:17:49 | 000,099,384 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/08 22:17:49 | 000,007,859 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/08 22:17:49 | 000,001,167 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/08 09:46:25 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 06:45:22 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:37:55 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/05/08 06:37:55 | 000,000,414 | —- | C] () – C:\Windows\SysWow64\lame_acm.xml
[2011/05/08 06:37:55 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/05/08 06:37:54 | 002,600,448 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/05/08 06:37:54 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/08 06:37:54 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/08 06:37:54 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/05/08 06:36:15 | 000,001,166 | —- | C] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/08 06:10:55 | 000,001,409 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/08 06:10:41 | 000,001,443 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/08 06:09:30 | 000,000,290 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/08 06:09:30 | 000,000,272 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/07 16:04:59 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/07 16:04:48 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2011/05/07 16:01:07 | 1608,179,712 | -HS- | C] () – C:\hiberfil.sys
[2009/07/14 12:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 09:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 09:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 07:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 06:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 04:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 04:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2002/03/22 05:39:02 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\UNACEV2.DLL
========== LOP Check ==========
[2011/05/08 06:43:13 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:37:02 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/19 14:26:28 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/15 23:27:17 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/12 12:25:20 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/08 12:35:03 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/14 19:59:05 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/09 10:10:47 | 000,000,000 | —D | M] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2009/07/14 12:08:49 | 000,014,216 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/05/19 14:26:09 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 14:26:11 | 2144,239,616 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 12:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 12:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 12:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 12:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 03:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 11:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/08 06:38:01 | 000,000,221 | -HS- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 19/05/2011 15:05:13 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,84 Gb Free Space | 50,70% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS
Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"TeraCopy_is1" = TeraCopy 2.12
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{133EE96D-DBA6-4644-84A4-B2794505D669}" = Vimicro USB PC Camera
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B0625F16-B742-4F75-9FD8-20B47ACC7DE2}" = ACDSee 7.0 PowerPack
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{BBF79EFA-3F63-43BC-88EE-0157CE50F1B1}" = Lenovo Camera
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ashampoo Burning Studio 8_is1" = Ashampoo Burning Studio 8.03
"DVDFab 6_is1" = DVDFab 6.2.0.5 (11/11/2009)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Stylus Photo R285_290 User’s Guide" = EPSON Stylus Photo R285_290 Manual
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.0.0
"LogMeIn Hamachi" = LogMeIn Hamachi
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 07/05/2011 22:25:28 | Computer Name = Nyoo-PC | Source = MsiInstaller | ID = 10005
Description = Product: LogMeIn Hamachi – A newer version (2.0.3.111) of Hamachi
has been found on the system. To downgrade, uninstall before proceeding.
Error - 07/05/2011 22:25:40 | Computer Name = Nyoo-PC | Source = MsiInstaller | ID = 10005
Description = Product: LogMeIn Hamachi – A newer version (2.0.3.111) of Hamachi
has been found on the system. To downgrade, uninstall before proceeding.
Error - 14/05/2011 2:59:36 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0x3cc Faulting application
start time: 0x01cc12047bcccb34 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: ba4149ab-7df7-11e0-80b7-001cc0ae3591
Error - 14/05/2011 3:00:08 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0x534 Faulting application
start time: 0x01cc12048f34a310 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: ccfb5d13-7df7-11e0-80b7-001cc0ae3591
Error - 14/05/2011 3:14:42 | Computer Name = Nyoo-PC | Source = Application Error | ID = 1000
Description = Faulting application name: AutoPlay.exe, version: 1.0.0.1, time stamp:
0xa0a0a0a0 Faulting module name: AutoPlay.exe, version: 1.0.0.1, time stamp: 0xa0a0a0a0
Exception
code: 0xc0000005 Fault offset: 0x0024b08d Faulting process id: 0xc4 Faulting application
start time: 0x01cc120698294845 Faulting application path: F:\AutoPlay.exe Faulting
module path: F:\AutoPlay.exe Report Id: d61879ad-7df9-11e0-80b7-001cc0ae3591
Error - 18/05/2011 11:26:54 | Computer Name = Nyoo-PC | Source = Application Hang | ID = 1002
Description = The program Searchqu Toolbar uninstall.exe version 4.1.0.1 stopped
interacting with Windows and was closed. To see if more information about the problem
is available, check the problem history in the Action Center control panel. Process
ID: fe4 Start Time: 01cc156fc43f0347 Termination Time: 0 Application Path: C:\Users\NYOO'S~1\AppData\Local\Temp\nso747A.tmp\Searchqu
Toolbar uninstall.exe Report Id:
[ Media Center Events ]
Error - 07/05/2011 19:51:57 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 16:51:57 - Error connecting to the internet. 16:51:57 - Unable
to contact server..
Error - 08/05/2011 22:29:57 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 19:29:57 - Error connecting to the internet. 19:29:57 - Unable
to contact server..
Error - 11/05/2011 0:48:06 | Computer Name = Nyoo-PC | Source = MCUpdate | ID = 0
Description = 21:48:06 - Error connecting to the internet. 21:48:06 - Unable
to contact server..
[ System Events ]
Error - 16/05/2011 6:26:20 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
YOPIE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 16/05/2011 8:45:25 | Computer Name = Nyoo-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The
backup browser is stopping.
Error - 16/05/2011 20:30:38 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 17/05/2011 2:31:20 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 17/05/2011 2:40:22 | Computer Name = Nyoo-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The
backup browser is stopping.
Error - 17/05/2011 10:10:45 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 17/05/2011 11:38:41 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 18/05/2011 7:14:25 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
YOPIE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 18/05/2011 9:44:16 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
COMPUTER_1 that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
Error - 19/05/2011 3:29:21 | Computer Name = Nyoo-PC | Source = bowser | ID = 8003
Description = The master browser has received a server announcement from the computer
FECEHAWE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{94A76781-1C8C-4813-91BA-0B90F50A8251}. The master browser is stopping
or an election is being forced.
< End of report >
My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Might have been better… but don't worry about it right now. Just carry on with the following instructions:After I do the scan, I reinstall my firefox 3.6.3, does that mean I had to rescan again?
Double click on OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
- Do Not copy the word CODE
- please note the fix starts with the :
:Processes
:OTL
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q="
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Then click the Run Fix button at the top
- Let the program run unhindered
- Please save the resulting log to be posted in your next reply.
- Reboot your computer
I copied the code then pasted it in OTL. I did the wrong thing by using run scan first. Then I do the Run FIx. However, the only log I get isn't the OTL log, but this log:
All processes killed
========== PROCESSES ==========
========== OTL ==========
No active process named Program Files was found!
Prefs.js: "Web Search" removed from browser.search.defaultenginename
Prefs.js: "Web Search" removed from browser.search.order.1
Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully.
File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully.
File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64 folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\content folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\components folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON Stylus Photo R290 Series deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.
File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}\ not found.
File {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Nyoo's Family\Desktop\cmd.bat deleted successfully.
C:\Users\Nyoo's Family\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Nyoo's Family
->Temp folder emptied: 42286031 bytes
->Temporary Internet Files folder emptied: 33141907 bytes
->FireFox cache emptied: 57361523 bytes
->Flash cache emptied: 3235 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10195492 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 136,00 mb
OTL by OldTimer - Version 3.2.22.3 log created on 05202011_220020
Files\Folders moved on Reboot…
C:\Users\Nyoo's Family\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot…
OTL logfile created on: 20/05/2011 21:57:32 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nyoo's Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 68,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 37,17 Gb Total Space | 18,78 Gb Free Space | 50,52% Space Free | Partition Type: NTFS
Drive D: | 24,41 Gb Total Space | 15,27 Gb Free Space | 62,54% Space Free | Partition Type: NTFS
Drive E: | 50,11 Gb Total Space | 28,25 Gb Free Space | 56,37% Space Free | Partition Type: NTFS
Computer Name: NYOO-PC | User Name: Nyoo's Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Windows\VM30xSnap.exe (Vimicro)
========== Modules (SafeList) ==========
MOD - C:\Users\Nyoo's Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Internet Download Manager\idmmkb.dll (Tonec Inc.)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfPCI) – C:\Windows\SysNative\drivers\VSTBS26.SYS (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysNative\drivers\vm30xx64.sys (Vimicro Corporation)
DRV - (VM30xx64) Vimicro USB PC Camera (ZC0301) – C:\Windows\SysWOW64\drivers\vm30xx64.sys (Vimicro Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://id.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F9 F5 E8 31 0F CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.id/"
FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.http: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxies.telkom.net.id"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/19 15:47:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/19 15:47:20 | 000,000,000 | —D | M]
[2011/05/15 23:30:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Extensions
[2011/05/16 17:12:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla\Firefox\Profiles\4t4o1wwk.default\extensions
[2011/05/19 21:53:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/10 08:41:26 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/05/15 23:30:25 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES (X86)\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/05/08 09:50:10 | 000,000,000 | —D | M] (IDM CC) – C:\USERS\NYOO'S FAMILY\APPDATA\ROAMING\IDM\IDMMZCC3
O1 HOSTS File: ([2009/06/11 04:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [VM30xSnap] C:\Windows\VM30xSnap.exe (Vimicro)
O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/19 15:47:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/19 14:58:35 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\index.php_files
[2011/05/18 22:05:21 | 012,521,992 | —- | C] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/05/15 23:27:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\PackageAware
[2011/05/14 14:12:07 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2011/05/14 14:12:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe Systems Shared
[2011/05/14 13:39:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Creativity Suite
[2011/05/14 13:39:43 | 000,000,000 | —D | C] – C:\ProgramData\UDL
[2011/05/14 13:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Print CD
[2011/05/14 13:38:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON Print CD
[2011/05/14 13:37:04 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2011/05/14 13:37:04 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2011/05/14 13:37:04 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2011/05/14 13:37:04 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2011/05/14 13:37:04 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2011/05/14 13:36:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\EPSON
[2011/05/14 13:36:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2011/05/14 13:36:46 | 000,000,000 | —D | C] – C:\ProgramData\EPSON
[2011/05/14 13:34:08 | 000,008,704 | —- | C] (SEIKO EPSON CORP.) – C:\Windows\SysNative\E_GCINST.DLL
[2011/05/14 13:34:05 | 000,129,536 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_ILMCKP.DLL
[2011/05/14 13:34:05 | 000,086,528 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysNative\E_IBCBCKP.DLL
[2011/05/14 13:33:59 | 000,000,000 | —D | C] – C:\Program Files\EPSON
[2011/05/14 07:09:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/05/12 12:23:31 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\MysteryStudio
[2011/05/12 12:22:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple Computer
[2011/05/12 12:22:08 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Apple Computer
[2011/05/12 12:22:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2011/05/12 12:21:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/12 12:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/12 12:20:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/12 12:20:44 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/12 12:20:38 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Apple
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/12 12:20:36 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\skypePM
[2011/05/10 08:44:42 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/10 08:40:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/05/10 08:40:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2011/05/10 08:27:52 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Skype
[2011/05/10 08:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/05/10 08:17:37 | 000,000,000 | —D | C] – C:\Lenovo Camera
[2011/05/10 08:17:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Camera
[2011/05/10 08:17:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Filter
[2011/05/10 08:17:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lenovo Camera
[2011/05/10 08:13:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vimicro USB PC Camera (ZC030x)
[2011/05/10 08:13:40 | 001,330,688 | —- | C] (Vimicro Corporation) – C:\Windows\SysNative\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 001,330,688 | R— | C] (Vimicro Corporation) – C:\Windows\SysWow64\drivers\vm30xx64.sys
[2011/05/10 08:13:39 | 000,249,856 | R— | C] (Vimicro) – C:\Windows\SysWow64\VM30xPRP.Ax
[2011/05/10 08:13:39 | 000,057,344 | R— | C] (Vimicro ) – C:\Windows\vm30xcap.exe
[2011/05/10 08:13:39 | 000,053,248 | R— | C] (Vimicro) – C:\Windows\VM30xSnap.exe
[2011/05/10 08:13:35 | 000,023,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drivers\usbcamd2.sys
[2011/05/10 08:13:34 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/05/10 08:13:34 | 000,348,160 | R— | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/05/10 08:12:57 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\InstallShield
[2011/05/09 10:10:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 6
[2011/05/09 09:59:13 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/05/09 09:21:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2011/05/09 09:21:07 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2011/05/09 09:20:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2011/05/09 09:20:58 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2011/05/09 09:19:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 22:17:49 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Vso
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\PcSetup
[2011/05/08 22:17:48 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\DVDFab
[2011/05/08 22:17:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 6
[2011/05/08 13:20:43 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Games
[2011/05/08 12:35:03 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\RenPy
[2011/05/08 11:41:05 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Macromedia
[2011/05/08 09:54:36 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Adobe
[2011/05/08 09:54:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\IDM
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\Documents\Downloads
[2011/05/08 09:50:09 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\DMCache
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/05/08 09:50:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Internet Download Manager
[2011/05/08 09:28:51 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\LogMeIn Hamachi
[2011/05/08 09:28:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2011/05/08 09:24:35 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/08 07:00:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Mozilla
[2011/05/08 06:45:21 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Mozilla
[2011/05/08 06:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/05/08 06:44:13 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\TeraCopy
[2011/05/08 06:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2011/05/08 06:44:09 | 000,000,000 | —D | C] – C:\Program Files\TeraCopy
[2011/05/08 06:43:14 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ACDSee
[2011/05/08 06:43:07 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\ACD Systems
[2011/05/08 06:42:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\ProgramData\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ACD Systems
[2011/05/08 06:42:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\ACD Systems
[2011/05/08 06:42:10 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/05/08 06:41:10 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2011/05/08 06:41:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2011/05/08 06:39:58 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Adobe
[2011/05/08 06:38:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Player Classic
[2011/05/08 06:37:55 | 000,839,680 | —- | C] (http://www.mp3dev.org/) – C:\Windows\SysWow64\lameACM.acm
[2011/05/08 06:37:55 | 000,287,744 | —- | C] (Kristal StudioDFileDescription) – C:\Windows\SysWow64\divxa32.acm
[2011/05/08 06:37:55 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\SysWow64\mp3fhg.acm
[2011/05/08 06:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/05/08 06:37:54 | 000,630,784 | —- | C] (On2.com) – C:\Windows\SysWow64\vp7vfw.dll
[2011/05/08 06:37:54 | 000,391,680 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\I263_32.drv
[2011/05/08 06:37:54 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\SysWow64\yv12vfw.dll
[2011/05/08 06:37:54 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\SysWow64\ac3acm.acm
[2011/05/08 06:37:54 | 000,121,344 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[2011/05/08 06:37:54 | 000,039,936 | —- | C] (Disappearing Inc.) – C:\Windows\SysWow64\huffyuv.dll
[2011/05/08 06:37:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\K-Lite Codec Pack
[2011/05/08 06:37:02 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2011/05/08 06:36:15 | 000,000,000 | —D | C] – C:\ProgramData\ashampoo
[2011/05/08 06:36:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ashampoo
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/08 06:35:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinRAR
[2011/05/08 06:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/08 06:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2011/05/08 06:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/05/08 06:30:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/05/08 06:29:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/05/08 06:28:50 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft Help
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2011/05/08 06:28:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2011/05/08 06:28:42 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/05/08 06:28:26 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Searches
[2011/05/08 06:10:38 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/08 06:10:38 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/08 06:10:19 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Identities
[2011/05/08 06:10:04 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Contacts
[2011/05/08 06:10:00 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\VirtualStore
[2011/05/08 06:09:30 | 000,000,000 | –SD | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Videos
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Saved Games
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Pictures
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Music
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Links
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Favorites
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Downloads
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\Desktop
[2011/05/08 06:09:30 | 000,000,000 | R–D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Temporary Internet Files
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Templates
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Start Menu
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\SendTo
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Recent
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\PrintHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\NetHood
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Videos
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Pictures
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Documents\My Music
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\My Documents
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Local Settings
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\History
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Cookies
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -HSD | C] – C:\Users\Nyoo's Family\AppData\Local\Application Data
[2011/05/08 06:09:30 | 000,000,000 | -H-D | C] – C:\Users\Nyoo's Family\AppData
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Temp
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Local\Microsoft
[2011/05/08 06:09:30 | 000,000,000 | —D | C] – C:\Users\Nyoo's Family\AppData\Roaming\Media Center Programs
[2011/05/08 06:09:03 | 000,000,000 | -HSD | C] – C:\Recovery
[2011/05/07 16:04:17 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/05/07 16:01:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2011/05/07 16:01:07 | 000,000,000 | -HSD | C] – C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2011/05/20 21:26:29 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 21:26:29 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 21:23:57 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/20 21:23:57 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/05/20 21:23:57 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/05/20 21:19:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/20 21:19:05 | 1608,179,712 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 15:47:23 | 000,001,963 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 15:47:23 | 000,001,939 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/19 15:24:18 | 000,006,494 | —- | M] () – C:\Users\Nyoo's Family\Documents\bookmarks-2011-05-19.json
[2011/05/19 15:02:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nyoo's Family\Desktop\OTL.exe
[2011/05/18 23:06:18 | 000,297,791 | —- | M] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/18 22:13:42 | 012,521,992 | —- | M] (Mozilla) – C:\Users\Nyoo's Family\Documents\Firefox Setup 4.0.1.exe
[2011/05/14 20:02:17 | 001,660,864 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 20:01:47 | 001,648,820 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 20:01:09 | 001,743,628 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 19:59:55 | 001,647,664 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 19:57:51 | 000,002,058 | —- | M] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:24 | 030,476,905 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | M] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 13:33:48 | 000,000,025 | —- | M] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/12 12:09:50 | 000,000,016 | —- | M] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:44:51 | 000,000,056 | -H– | M] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:40:47 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:29:56 | 000,000,937 | —- | M] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/10 08:17:21 | 000,001,918 | —- | M] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/09 10:10:44 | 000,099,384 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/09 10:10:44 | 000,082,816 | —- | M] (VSO Software) – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.sys
[2011/05/09 10:10:44 | 000,007,859 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/09 10:10:44 | 000,001,167 | —- | M] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/09 10:10:42 | 000,000,955 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | M] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | M] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/08 22:17:49 | 000,082,816 | —- | M] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2011/05/08 09:46:25 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 09:08:12 | 000,341,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/08 06:45:22 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | M] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:36:15 | 000,001,166 | —- | M] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/05/07 16:05:16 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiicdxx.dat
========== Files Created - No Company Name ==========
[2011/05/19 15:47:23 | 000,001,963 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/19 15:47:23 | 000,001,939 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/19 15:24:18 | 000,006,494 | —- | C] () – C:\Users\Nyoo's Family\Documents\bookmarks-2011-05-19.json
[2011/05/18 23:06:14 | 000,297,791 | —- | C] () – C:\Users\Nyoo's Family\Documents\index.php.htm
[2011/05/14 19:57:51 | 000,002,058 | —- | C] () – C:\Users\Nyoo's Family\Desktop\Adobe Photoshop CS.lnk
[2011/05/14 14:22:22 | 030,476,905 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.psd
[2011/05/14 14:12:04 | 000,002,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2011/05/14 14:12:04 | 000,002,065 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS.lnk
[2011/05/14 14:12:04 | 000,002,058 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS.lnk
[2011/05/14 14:09:24 | 001,665,845 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4705.JPG
[2011/05/14 14:09:12 | 001,660,864 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4704.JPG
[2011/05/14 14:09:00 | 001,648,820 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4703.JPG
[2011/05/14 14:07:52 | 001,743,628 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4702.JPG
[2011/05/14 14:07:28 | 001,647,664 | —- | C] () – C:\Users\Nyoo's Family\Documents\DSCN4701.JPG
[2011/05/14 13:37:04 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/05/14 13:37:04 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2011/05/14 13:37:04 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2011/05/14 13:37:04 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2011/05/14 13:37:04 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2011/05/14 13:37:04 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2011/05/14 13:37:04 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2011/05/14 13:37:04 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2011/05/14 13:37:04 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2011/05/14 13:37:04 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2011/05/14 13:37:04 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2011/05/14 13:37:04 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2011/05/14 13:37:04 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2011/05/14 13:37:04 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2011/05/14 13:37:04 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2011/05/14 13:37:04 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2011/05/14 13:37:04 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2011/05/14 13:37:04 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2011/05/14 13:37:04 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2011/05/14 13:37:04 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2011/05/14 13:37:04 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/05/14 13:37:04 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/05/14 13:37:04 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/05/14 13:37:04 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/05/14 13:37:04 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2011/05/14 13:37:04 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2011/05/14 13:37:04 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/05/14 13:37:04 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2011/05/14 13:33:48 | 000,000,025 | —- | C] () – C:\Windows\CDE SPR290Asia.ini
[2011/05/14 07:09:08 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/12 12:20:37 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/10 08:44:51 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/05/10 08:27:21 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/05/10 08:17:42 | 000,000,016 | —- | C] () – C:\Windows\strSaveHwnd.ini
[2011/05/10 08:17:21 | 000,001,918 | —- | C] () – C:\Users\Public\Desktop\Lenovo Camera.lnk
[2011/05/10 08:13:39 | 000,049,152 | R— | C] () – C:\Windows\amcap.exe
[2011/05/10 08:13:36 | 000,138,752 | —- | C] () – C:\Windows\VM303Uninst64.exe
[2011/05/10 08:13:36 | 000,073,728 | —- | C] () – C:\Windows\VMInstNT.exe
[2011/05/10 08:13:36 | 000,069,632 | —- | C] () – C:\Windows\VMInst64.exe
[2011/05/10 08:13:35 | 000,040,960 | —- | C] () – C:\Windows\VM303UninstNT.exe
[2011/05/09 10:10:42 | 000,000,955 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 6.lnk
[2011/05/09 10:10:42 | 000,000,931 | —- | C] () – C:\Users\Nyoo's Family\Desktop\DVDFab 6.lnk
[2011/05/09 09:21:08 | 000,002,043 | —- | C] () – C:\Users\Public\Desktop\PowerDVD.lnk
[2011/05/09 09:08:52 | 000,000,937 | —- | C] () – C:\Users\Nyoo's Family\Desktop\soundgame - Shortcut.lnk
[2011/05/08 22:17:49 | 000,099,384 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\inst.exe
[2011/05/08 22:17:49 | 000,007,859 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.cat
[2011/05/08 22:17:49 | 000,001,167 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\pcouffin.inf
[2011/05/08 09:46:25 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/05/08 06:45:22 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/08 06:38:01 | 000,001,437 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 06:37:55 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/05/08 06:37:55 | 000,000,414 | —- | C] () – C:\Windows\SysWow64\lame_acm.xml
[2011/05/08 06:37:55 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/05/08 06:37:54 | 002,600,448 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2011/05/08 06:37:54 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011/05/08 06:37:54 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011/05/08 06:37:54 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/05/08 06:36:15 | 000,001,166 | —- | C] () – C:\Users\Public\Desktop\Ashampoo Burning Studio 8.lnk
[2011/05/08 06:10:55 | 000,001,409 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/08 06:10:41 | 000,001,443 | —- | C] () – C:\Users\Nyoo's Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/08 06:09:30 | 000,000,290 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/08 06:09:30 | 000,000,272 | —- | C] () – C:\Users\Nyoo's Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/07 16:04:59 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/07 16:04:48 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/05/07 16:03:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2011/05/07 16:01:07 | 1608,179,712 | -HS- | C] () – C:\hiberfil.sys
[2009/07/14 12:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 09:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 09:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 07:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 06:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 04:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 04:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2002/03/22 05:39:02 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\UNACEV2.DLL
========== Custom Scans ==========
< :Processes >
< >
< :OTL >
< PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >
< FF - prefs.js..browser.search.defaultenginename: "Web Search" >
< FF - prefs.js..browser.search.order.1: "Web Search" >
< FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;=" >
< O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >
< O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >
< O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) >
< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD) >
< O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD) >
< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD) >
< O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) >
< [2011/05/15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar >
Invalid Switch: 15 23:30:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
< O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. >
< O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. >
< O4 - HKCU..\Run: [EPSON Stylus Photo R290 Series] File not found >
< O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found >
< O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found >
< O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found >
Invalid Switch: pagefile) - File not found
< O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found >
Invalid Switch: pagefile) - File not found
< O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. >
< O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. >
< >
< :Files >
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
< >
< :Commands >
< [purity] >
< [emptytemp] >
< [start explorer] >
< [Reboot] >
< End of report >
You did fine. The "fix" log you provided is correct.
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
One little entry still hanging on…
COMBOFIX-Script
- Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
DDS:: uStart Page = hxxp://www.searchqu.com/406
- Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
[external image: Posted Image]
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Looking good.
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
- Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox. - Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
- When prompted allow the Add-On/Active X to install.
- Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
- Now click on Advanced Settings and select the following:
- Scan for potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth Technology
- Now click on: [external image: Posted Image]
- The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
- When completed the Online Scan will begin automatically.
- Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
- When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
- Now click on: [external image: Posted Image]
- Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
- Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Also let me know how things seem to be running.
That is interesting because I have tried it in Internet Explorer, Chrome, and Firefox and all give me the same thing:
STEP ONE: Run free on-demand scan
ESET Online Scanner a fast and and free tool that detects and removes threats on your PC. Utilizing only your browser, it scans your computer with ESET's award-winning ThreatSense engine.
[external image: Posted Image]
Maybe the page reads differently when accessed from different countries, but based upon what you are telling me… clicking on "Run ESET Online Scanner" would seem like the appropriate thing to do.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI