This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

http://www.searchqu.com/406

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi WhattheTech!

I accidentally installed Bandoo onto my computer and ever since the installation, "http://www.searchqu.com/406" has been my homepage on my browser.

My attempt to get rid of the problem myself consisted of:

- Uninstalling Bandoo
- Change my homepage

Unfortunately, searchqu.com remains as the homepage.

I downloaded HiJackThis and the following are my scan results:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:09:02 PM, on 03/06/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Matthew\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: FCTBPos00Pos - {9EBF8AAF-0A31-4786-909A-97A0EF101743} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AddThis Toolbar - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coIEPlg.dll
O3 - Toolbar: FreeRIP.com Toolbar - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files (x86)\FreeRIP3\toolband.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\WI3C8A~1\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WorkForce 310(Network)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFHA.EXE /FU "C:\Users\Paculan\AppData\Local\Temp\E_SBEF3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4137015761-1925706532-750459329-1004\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW (User 'Matthew')
O4 - Startup: Epson all-in-one Registration.lnk = E:\Common\EpsonReg\EpsonReg.exe
O8 - Extra context menu item: &FreeRIP Search - res://C:\Program Files (x86)\FreeRIP3\toolband.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O20 - AppInit_DLLs: c:\progra~2\wi3c8a~1\datamngr\datamngr.dll c:\progra~2\wi3c8a~1\datamngr\iebho.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13489 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there,

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click, choose "Run as Administrator")


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
—————————————————————————————————

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

===================================================

On your next reply please post :
OTL log
aswMBR log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire! Thanks for your help!

OTL.Txt log:

OTL logfile created on: 04/06/2011 9:00:18 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Matthew\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 54.27% Memory free
5.50 Gb Paging File | 3.85 Gb Available in Paging File | 69.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.48 Gb Total Space | 353.67 Gb Free Space | 77.65% Space Free | Partition Type: NTFS
Drive D: | 10.18 Gb Total Space | 1.50 Gb Free Space | 14.77% Space Free | Partition Type: NTFS

Computer Name: PACULAN-PC | User Name: Paculan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe ()
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (EpsonBidirectionalService) – C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (seehcri) – C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggsemc) – C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) – C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0403000.005\ironx64.sys (Symantec Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (TASCAM_US122L_WDM) – C:\Windows\SysNative\drivers\tscusb2a.sys (TASCAM)
DRV:64bit: - (TASCAM_US122144) – C:\Windows\SysNative\drivers\tascusb2.sys (TASCAM)
DRV:64bit: - (TASCAM_US122L_MIDI) – C:\Windows\SysNative\drivers\tscusb2m.sys (TASCAM)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symds64.sys (Symantec Corporation)
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SynasUSB) – C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110604.003\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110604.003\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110603.003\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 39 2C A2 33 CF CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/08/13 14:00:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/08/12 15:18:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/26 12:38:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/26 12:38:20 | 000,000,000 | —D | M]

[2011/05/27 17:29:50 | 000,000,000 | —D | M] (No name found) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions
[2011/05/27 17:29:51 | 000,000,000 | —D | M] (Bandoo for Firefox) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions\[removed]
[2011/05/27 17:28:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O2 - BHO: (AddThis Toolbar BHO) - {9EBF8AAF-0A31-4786-909A-97A0EF101743} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (FreeRIP.com Toolbar) - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
O3 - HKLM\..\Toolbar: (AddThis Toolbar) - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (FreeRIP.com Toolbar) - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AddThis Toolbar) - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [WorkForce 310(Network)] File not found
O4 - Startup: C:\Users\Paculan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &FreeRIP; Search - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8 - Extra context menu item: &FreeRIP; Search - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (c:\progra~2\wi3c8a~1\datamngr\datamngr.dll) - c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (c:\progra~2\wi3c8a~1\datamngr\iebho.dll) - c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/27 17:29:50 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Roaming\Mozilla
[2011/05/27 17:28:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2011/05/27 17:28:00 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Local\PackageAware
[2011/05/25 02:14:20 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 03:53:47 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/24 03:53:47 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/11 18:25:38 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/11 18:25:37 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/11 18:25:36 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/11 18:25:31 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/05/11 18:25:31 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/05/08 17:42:06 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:05 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/04 20:54:15 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/04 20:52:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/04 20:41:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/03 14:58:56 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/03 14:58:56 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/03 14:54:51 | 000,733,376 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/03 14:54:51 | 000,632,610 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/03 14:54:51 | 000,112,338 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/03 14:50:50 | 2214,043,648 | -HS- | M] () – C:\hiberfil.sys
[2011/06/02 12:55:24 | 000,001,492 | —- | M] () – C:\ProgramData\ss.ini
[2011/05/31 10:00:00 | 000,000,544 | —- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2011/05/27 17:30:03 | 000,000,034 | —- | M] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/05/18 12:29:02 | 000,002,270 | —- | M] () – C:\Users\Public\Desktop\Sony Ericsson PC Companion 2.0.lnk
[2011/05/09 07:18:26 | 000,001,443 | —- | M] () – C:\Users\Paculan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 17:42:06 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:06 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:05 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2011/05/08 17:42:02 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/08 17:42:05 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:02 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/02/19 01:03:40 | 000,000,034 | —- | C] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/02/19 01:03:37 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/09/16 12:31:45 | 000,002,892 | —- | C] () – C:\Windows\SysWow64\audcon.sys
[2010/09/06 17:40:08 | 000,735,176 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/11 16:28:49 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/06/15 18:28:32 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/06/15 18:28:32 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/06/15 18:28:32 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/06/15 18:28:32 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/06/15 18:28:32 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/06/15 18:28:32 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/06/15 18:28:32 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/06/15 18:28:32 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/06/15 18:28:32 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/06/15 18:28:32 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/06/15 18:28:32 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/06/15 18:28:32 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/06/15 18:23:12 | 000,000,079 | —- | C] () – C:\Windows\EPWF310.ini
[2009/09/29 19:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2011/06/03 14:50:50 | 2214,043,648 | -HS- | M] () – C:\hiberfil.sys
[2011/04/30 11:09:21 | 000,000,080 | —- | M] () – C:\log.txt
[2006/12/02 03:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/06/03 14:50:52 | 2952,060,928 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/09 07:18:26 | 000,000,221 | -HS- | M] () – C:\Users\Paculan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Extras.Txt log:


OTL Extras logfile created on: 04/06/2011 9:00:18 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Matthew\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 54.27% Memory free
5.50 Gb Paging File | 3.85 Gb Available in Paging File | 69.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.48 Gb Total Space | 353.67 Gb Free Space | 77.65% Space Free | Partition Type: NTFS
Drive D: | 10.18 Gb Total Space | 1.50 Gb Free Space | 14.77% Space Free | Partition Type: NTFS

Computer Name: PACULAN-PC | User Name: Paculan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{23B45E10-0CA5-43E9-BD6D-C2BD6CBE11AC}" = iTunes
"{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"EPSON WorkForce 310 Series" = EPSON WorkForce 310 Series Printer Uninstall
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"USB_AUDIO_DEusb-audio.deTascam" = US-122 MKII / US-144 MKII

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150170}" = J2SE Runtime Environment 5.0 Update 17
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{43523FEF-9D8E-4572-BB11-0E914D366E0A}" = LightScribe Template Labeler
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4640FDE1-B83A-4376-84ED-86F86BEE2D41}" = Driver Detective
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{501451DE-5808-4599-B544-8BD0915B6B24}_is1" = FreeRIP v3.5
"{520CD4F0-9DAC-4C5C-8CA1-D0210CFF6062}" = Media Go
"{605C0E57-BBB8-458F-9020-B17DCF0D5DEA}" = LightScribe Template Designs - Floral Pack 1
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{741CFE3A-1C0B-4A7D-8E08-5D78C911C09D}" = HP Support Assistant
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140011-0062-0409-0000-0000000FF1CE}" = Microsoft Office Home and Business 2010 - English
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB3C4AC6-C401-4132-A8B5-265899A9C0E8}" = Steinberg Cubase LE 4
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.01.173
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FFFAE01B-466F-4C07-9821-A94FD753BDDA}" = EpsonNet Setup
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"AddThis Toolbar" = AddThis Toolbar
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"N360" = Norton 360
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Syncrosoft License Control" = Syncrosoft License Control
"Update Engine" = Sony Ericsson Update Engine
"Update Service" = Sony Ericsson Update Service
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 23/04/2011 11:18:00 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 23/04/2011 11:18:00 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5007

Error - 23/04/2011 11:18:00 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5007

Error - 23/04/2011 11:18:01 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 23/04/2011 11:18:01 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6006

Error - 23/04/2011 11:18:01 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6006

Error - 23/04/2011 11:18:02 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 23/04/2011 11:18:02 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7004

Error - 23/04/2011 11:18:02 PM | Computer Name = Paculan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7004

Error - 24/04/2011 12:31:01 AM | Computer Name = Paculan-PC | Source = EventSystem | ID = 4622
Description =

[ Hewlett-Packard Events ]
Error - 01/08/2010 8:34:01 PM | Computer Name = Paculan-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)

[ System Events ]
Error - 03/06/2011 7:38:07 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 7:50:05 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 8:02:07 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 8:14:08 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 9:38:04 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 9:50:02 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 10:02:01 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 10:49:57 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 03/06/2011 11:01:56 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =

Error - 04/06/2011 8:43:46 PM | Computer Name = Paculan-PC | Source = bowser | ID = 8003
Description =


< End of report >


aswMBR log:

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-04 21:24:13
—————————–
21:24:13.847 OS Version: Windows x64 6.1.7600
21:24:13.847 Number of processors: 2 586 0x602
21:24:13.847 ComputerName: PACULAN-PC UserName: Paculan
21:24:16.311 Initialize success
21:25:13.298 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000061
21:25:13.298 Disk 0 Vendor: Hitachi_ JP2O Size: 476940MB BusType: 3
21:25:15.357 Disk 0 MBR read successfully
21:25:15.357 Disk 0 MBR scan
21:25:15.357 Disk 0 unknown MBR code
21:25:15.373 Service scanning
21:25:16.340 Disk 0 trace - called modules:
21:25:16.371 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
21:25:16.371 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80032da790]
21:25:16.387 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8002cca390]
21:25:16.387 5 ACPI.sys[fffff88000f7b781] -> nt!IofCallDriver -> \Device\00000061[0xfffffa8003094060]
21:25:16.387 Scan finished successfully
21:35:51.604 Disk 0 MBR has been saved successfully to "C:\Users\Matthew\Desktop\MBR.dat"
21:35:51.604 The log file has been saved successfully to "C:\Users\Matthew\Desktop\aswMBR.txt"
Hi,

You're welcome. :)

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O2 - BHO: (AddThis Toolbar BHO) - {9EBF8AAF-0A31-4786-909A-97A0EF101743} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (FreeRIP.com Toolbar) - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - File not found
    O3 - HKLM\..\Toolbar: (AddThis Toolbar) - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (FreeRIP.com Toolbar) - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (AddThis Toolbar) - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
    O8:64bit: - Extra context menu item: &FreeRIP Search - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
    O8 - Extra context menu item: &FreeRIP Search - C:\Program Files (x86)\FreeRIP3\toolband.dll ()
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_17)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (c:\progra~2\wi3c8a~1\datamngr\datamngr.dll) - c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (c:\progra~2\wi3c8a~1\datamngr\iebho.dll) - c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
    [2011/05/27 17:28:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [REBOOT]
    [RESETHOSTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script and( don't check the boxes beside LOP Check or Purity this time )
===================================================

On your next reply please post :
OTL fix log
Fresh OTL log
How is it running now?


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Just a few questions: By "reboot", you mean restart my computer? When I rerun OTL after I reboot, do I just click "Run Scan"? You said "don't check the boxes beside LOP Check or Purity this time". I don't believe I checked them last time. Is this an issue at all?
Don't worry about the command, it will do it automatically for you. That is correct for the Run Scan. No not an issue at all.
Alright, thanks for your patience Conspire!

OTL fix log:

All processes killed
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9EBF8AAF-0A31-4786-909A-97A0EF101743}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EBF8AAF-0A31-4786-909A-97A0EF101743}\ deleted successfully.
C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{081230F8-EA50-42A9-983C-D22ABC2EED3B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{081230F8-EA50-42A9-983C-D22ABC2EED3B}\ deleted successfully.
C:\Program Files (x86)\FreeRIP3\toolband.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B43176CC-4D9E-493B-A636-D9CBFE39C6DA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B43176CC-4D9E-493B-A636-D9CBFE39C6DA}\ deleted successfully.
File C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{081230F8-EA50-42A9-983C-D22ABC2EED3B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{081230F8-EA50-42A9-983C-D22ABC2EED3B}\ not found.
File C:\Program Files (x86)\FreeRIP3\toolband.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B43176CC-4D9E-493B-A636-D9CBFE39C6DA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B43176CC-4D9E-493B-A636-D9CBFE39C6DA}\ not found.
File C:\Program Files (x86)\AddThis Toolbar\Toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&FreeRIP; Search\ deleted successfully.
File C:\Program Files (x86)\FreeRIP3\toolband.dll not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&FreeRIP; Search\ not found.
File C:\Program Files (x86)\FreeRIP3\toolband.dll not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-4137015761-1925706532-750459329-1004\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-4137015761-1925706532-750459329-1004\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-4137015761-1925706532-750459329-1004\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully.
File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\wi3c8a~1\datamngr\datamngr.dll deleted successfully.
c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\wi3c8a~1\datamngr\iebho.dll deleted successfully.
File c:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\components folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\searchbar folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\options folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\uwa folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin\lib folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\skin folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2 folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\widgets folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\modules folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\lib folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\data\search folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content\data folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome\content folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\chrome folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64 folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\content folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension\components folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\FirefoxExtension folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr folder moved successfully.
C:\Program Files (x86)\Windows iLivid Toolbar folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Matthew\Desktop\cmd.bat deleted successfully.
C:\Users\Matthew\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Arlene
->Flash cache emptied: 75968 bytes

User: Dad
->Flash cache emptied: 116035 bytes

User: Default
->Flash cache emptied: 56504 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Matthew
->Flash cache emptied: 249969 bytes

User: Paculan
->Flash cache emptied: 16090 bytes

User: Public

User: Tita Nels
->Flash cache emptied: 70200 bytes

Total Flash Files Cleaned = 1.00 mb


[EMPTYTEMP]

User: All Users

User: Arlene
->Temp folder emptied: 3152529 bytes
->Temporary Internet Files folder emptied: 298907344 bytes
->Java cache emptied: 89906833 bytes
->FireFox cache emptied: 3770024 bytes
->Flash cache emptied: 0 bytes

User: Dad
->Temp folder emptied: 1094 bytes
->Temporary Internet Files folder emptied: 938 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Matthew
->Temp folder emptied: 3082025 bytes
->Temporary Internet Files folder emptied: 5818732 bytes
->Java cache emptied: 87919242 bytes
->FireFox cache emptied: 47633529 bytes
->Flash cache emptied: 0 bytes

User: Paculan
->Temp folder emptied: 3216742 bytes
->Temporary Internet Files folder emptied: 171965 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Tita Nels
->Temp folder emptied: 480 bytes
->Temporary Internet Files folder emptied: 871 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 39829248 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3544276 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 102023 bytes
RecycleBin emptied: 513824 bytes

Total Files Cleaned = 560.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.23.0 log created on 06062011_113928

Files\Folders moved on Reboot…
File move failed. C:\Users\Matthew\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…


Fresh OTL log:

OTL logfile created on: 06/06/2011 12:02:52 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Matthew\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 59.93% Memory free
5.50 Gb Paging File | 4.06 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.48 Gb Total Space | 355.78 Gb Free Space | 78.11% Space Free | Partition Type: NTFS
Drive D: | 10.18 Gb Total Space | 1.50 Gb Free Space | 14.77% Space Free | Partition Type: NTFS

Computer Name: PACULAN-PC | User Name: Paculan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe ()
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (EpsonBidirectionalService) – C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (seehcri) – C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggsemc) – C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) – C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0403000.005\ironx64.sys (Symantec Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (TASCAM_US122L_WDM) – C:\Windows\SysNative\drivers\tscusb2a.sys (TASCAM)
DRV:64bit: - (TASCAM_US122144) – C:\Windows\SysNative\drivers\tascusb2.sys (TASCAM)
DRV:64bit: - (TASCAM_US122L_MIDI) – C:\Windows\SysNative\drivers\tscusb2m.sys (TASCAM)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symds64.sys (Symantec Corporation)
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SynasUSB) – C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110605.002\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110605.002\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110603.003\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 39 2C A2 33 CF CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/08/13 14:00:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/08/12 15:18:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/26 12:38:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/26 12:38:20 | 000,000,000 | —D | M]

[2011/05/27 17:29:50 | 000,000,000 | —D | M] (No name found) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions
[2011/05/27 17:29:51 | 000,000,000 | —D | M] (Bandoo for Firefox) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions\[removed]
[2011/05/27 17:28:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/06 11:41:28 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [WorkForce 310(Network)] File not found
O4 - Startup: C:\Users\Paculan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/06 11:39:28 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/27 17:29:50 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Roaming\Mozilla
[2011/05/27 17:28:00 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Local\PackageAware
[2011/05/25 02:14:20 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 03:53:47 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/24 03:53:47 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/11 18:25:38 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/11 18:25:37 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/11 18:25:36 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/11 18:25:31 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/05/11 18:25:31 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/05/08 17:42:06 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:05 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/06 11:57:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/06 11:50:12 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 11:50:12 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 11:42:44 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/06 11:42:27 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/06 11:42:24 | 2214,043,648 | -HS- | M] () – C:\hiberfil.sys
[2011/06/06 11:41:28 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2011/06/05 12:07:15 | 000,733,376 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/05 12:07:15 | 000,632,610 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/05 12:07:15 | 000,112,338 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/02 12:55:24 | 000,001,492 | —- | M] () – C:\ProgramData\ss.ini
[2011/05/31 10:00:00 | 000,000,544 | —- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2011/05/27 17:30:03 | 000,000,034 | —- | M] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/05/18 12:29:02 | 000,002,270 | —- | M] () – C:\Users\Public\Desktop\Sony Ericsson PC Companion 2.0.lnk
[2011/05/09 07:18:26 | 000,001,443 | —- | M] () – C:\Users\Paculan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 17:42:06 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:06 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:05 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2011/05/08 17:42:02 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/08 17:42:05 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:02 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/02/19 01:03:40 | 000,000,034 | —- | C] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/02/19 01:03:37 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/09/16 12:31:45 | 000,002,892 | —- | C] () – C:\Windows\SysWow64\audcon.sys
[2010/09/06 17:40:08 | 000,735,176 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/11 16:28:49 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/06/15 18:28:32 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/06/15 18:28:32 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/06/15 18:28:32 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/06/15 18:28:32 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/06/15 18:28:32 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/06/15 18:28:32 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/06/15 18:28:32 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/06/15 18:28:32 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/06/15 18:28:32 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/06/15 18:28:32 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/06/15 18:28:32 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/06/15 18:28:32 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/06/15 18:23:12 | 000,000,079 | —- | C] () – C:\Windows\EPWF310.ini
[2009/09/29 19:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >


I changed my homepage from "http://www.searchqu.com/406" to "www.google.ca" and the homepage remained as Google instead of switching back to searchqu.com this time!

Although on Firefox I went to View->Toolbars and "Searchqu Toolbar" is still there but it is unchecked.
On Internet Explorer I went to View->Toolbars, and there is no Searchqu Toolbar
Good to hear that :thumbup:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/05/27 17:29:51 | 000,000,000 | —D | M] (Bandoo for Firefox) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions\[removed]
    
    :Commands
    [REBOOT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script and( don't check the boxes beside LOP Check or Purity this time )

===================================================


On your next reply please post :
OTL fix log
Fresh OTL log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hey Conspire, I ran the "Fix", but no fix log appeared after the reboot. The "Searchqu Toolbar" is still in Firefox.

Here is this Scan I ran after reboot:

OTL logfile created on: 07/06/2011 11:35:04 AM - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Matthew\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 54.09% Memory free
5.50 Gb Paging File | 4.07 Gb Available in Paging File | 74.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 455.48 Gb Total Space | 355.56 Gb Free Space | 78.06% Space Free | Partition Type: NTFS
Drive D: | 10.18 Gb Total Space | 1.50 Gb Free Space | 14.77% Space Free | Partition Type: NTFS

Computer Name: PACULAN-PC | User Name: Paculan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe ()
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Modules (SafeList) ==========

MOD - C:\Users\Matthew\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (EpsonBidirectionalService) – C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (seehcri) – C:\Windows\SysNative\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggsemc) – C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) – C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0403000.005\ironx64.sys (Symantec Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0403000.005\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (TASCAM_US122L_WDM) – C:\Windows\SysNative\drivers\tscusb2a.sys (TASCAM)
DRV:64bit: - (TASCAM_US122144) – C:\Windows\SysNative\drivers\tascusb2.sys (TASCAM)
DRV:64bit: - (TASCAM_US122L_MIDI) – C:\Windows\SysNative\drivers\tscusb2m.sys (TASCAM)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\N360x64\0403000.005\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0403000.005\symds64.sys (Symantec Corporation)
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (SynasUSB) – C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110606.036\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20110606.036\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110603.003\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/CQCON/4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/CQCON/4
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 39 2C A2 33 CF CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/08/13 14:00:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/08/12 15:18:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/26 12:38:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/26 12:38:20 | 000,000,000 | —D | M]

[2011/06/07 11:23:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Paculan\AppData\Roaming\Mozilla\Firefox\extensions
[2011/05/27 17:28:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/06 11:41:28 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [PC-Doctor for Windows localizer] C:\Program Files\PC-Doctor for Windows\localizer.exe (PC-Doctor, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [WorkForce 310(Network)] File not found
O4 - Startup: C:\Users\Paculan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/06 11:39:28 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/27 17:29:50 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Roaming\Mozilla
[2011/05/27 17:28:00 | 000,000,000 | —D | C] – C:\Users\Paculan\AppData\Local\PackageAware
[2011/05/25 02:14:20 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 03:53:47 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/24 03:53:47 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/11 18:25:38 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/11 18:25:37 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/11 18:25:36 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/11 18:25:31 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/05/11 18:25:31 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/05/08 17:42:06 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:05 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/07 11:38:21 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/07 11:38:21 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/07 11:31:06 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/07 11:30:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/07 11:30:31 | 2214,043,648 | -HS- | M] () – C:\hiberfil.sys
[2011/06/06 22:57:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/06 11:41:28 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2011/06/05 12:07:15 | 000,733,376 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/05 12:07:15 | 000,632,610 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/05 12:07:15 | 000,112,338 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/02 12:55:24 | 000,001,492 | —- | M] () – C:\ProgramData\ss.ini
[2011/05/31 10:00:00 | 000,000,544 | —- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2011/05/27 17:30:03 | 000,000,034 | —- | M] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/05/18 12:29:02 | 000,002,270 | —- | M] () – C:\Users\Public\Desktop\Sony Ericsson PC Companion 2.0.lnk
[2011/05/09 07:18:26 | 000,001,443 | —- | M] () – C:\Users\Paculan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/08 17:42:06 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/05/08 17:42:06 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/05/08 17:42:06 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2011/05/08 17:42:06 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/05/08 17:42:05 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/05/08 17:42:05 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/08 17:42:05 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/05/08 17:42:05 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/08 17:42:05 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/05/08 17:42:05 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/08 17:42:05 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2011/05/08 17:42:05 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/05/08 17:42:05 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2011/05/08 17:42:05 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/08 17:42:05 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/05/08 17:42:05 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/05/08 17:42:05 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/05/08 17:42:05 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/08 17:42:05 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/05/08 17:42:05 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/08 17:42:05 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/05/08 17:42:05 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/05/08 17:42:05 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/08 17:42:05 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/08 17:42:05 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:05 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/08 17:42:05 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/05/08 17:42:05 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/05/08 17:42:05 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/05/08 17:42:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/05/08 17:42:05 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/08 17:42:05 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/08 17:42:05 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/05/08 17:42:04 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/05/08 17:42:04 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/05/08 17:42:04 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/08 17:42:04 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/08 17:42:04 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/05/08 17:42:04 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2011/05/08 17:42:03 | 002,303,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/05/08 17:42:03 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/05/08 17:42:03 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/05/08 17:42:03 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/05/08 17:42:03 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/05/08 17:42:03 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/08 17:42:03 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/05/08 17:42:03 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/08 17:42:03 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/08 17:42:03 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/05/08 17:42:03 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/05/08 17:42:03 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/05/08 17:42:03 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/05/08 17:42:03 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/05/08 17:42:02 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/05/08 17:42:02 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/08 17:42:02 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/05/08 17:42:02 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/05/08 17:42:02 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/08 17:42:02 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/05/08 17:42:02 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/08 17:42:02 | 000,236,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/05/08 17:42:02 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/05/08 17:42:02 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/05/08 17:42:02 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/08 17:42:02 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/05/08 17:42:02 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/08 17:42:02 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/05/08 17:42:02 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/08 17:42:02 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/08 17:42:02 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/05/08 17:42:02 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/05/08 17:42:02 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2011/05/08 17:42:02 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/05/08 17:42:02 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/08 17:42:02 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/08 17:42:02 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/08 17:42:01 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/08 17:42:01 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/05/08 17:42:01 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[1 C:\Users\Paculan\AppData\Local\*.tmp files -> C:\Users\Paculan\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/08 17:42:05 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2011/05/08 17:42:02 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/02/19 01:03:40 | 000,000,034 | —- | C] () – C:\Users\Paculan\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2011/02/19 01:03:37 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/09/16 12:31:45 | 000,002,892 | —- | C] () – C:\Windows\SysWow64\audcon.sys
[2010/09/06 17:40:08 | 000,735,176 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/11 16:28:49 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/06/15 18:28:32 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/06/15 18:28:32 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/06/15 18:28:32 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/06/15 18:28:32 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/06/15 18:28:32 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/06/15 18:28:32 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/06/15 18:28:32 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/06/15 18:28:32 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/06/15 18:28:32 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/06/15 18:28:32 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/06/15 18:28:32 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/06/15 18:28:32 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/06/15 18:28:32 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/06/15 18:28:32 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/06/15 18:23:12 | 000,000,079 | —- | C] () – C:\Windows\EPWF310.ini
[2009/09/29 19:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >
Let's see if MBAM can remove that.

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

On your next reply please post :
MBAM log
ESET log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Does this help?

NORTON 360
  • Right-click the Norton 360 Premier Edition icon in the system tray and select Disable Antivirus Automatic-Protect.
  • You will get a new dialog box with five options: 15 minutes, 1 hour, 5 hours, Until system restart, Permanently.
  • Choose 5 hours.
The option is unavailable on this account I'm using. But when I switch to the Administrator, I can select the "Disable Antivirus Automatic-Protect". Should I just switch over to the Administrator account and disable it then switch back here?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI