This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Ave.exe

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I use win 7 OS and i just got infected with ave.exe today, it was in my processes list so i ended the task, and now it isn't there anymore i don't think i removed though. it wont allow me to turn on my window security center and sone other problems.. please help me :( thanks in advance
OTL logfile created on: 7/24/2011 3:36:47 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Nianoor\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 66.20% Memory free
4.00 Gb Paging File | 3.27 Gb Available in Paging File | 81.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 20.00 Gb Total Space | 4.39 Gb Free Space | 21.94% Space Free | Partition Type: NTFS
Drive D: | 20.00 Gb Total Space | 11.10 Gb Free Space | 55.52% Space Free | Partition Type: NTFS
Drive E: | 29.99 Gb Total Space | 8.77 Gb Free Space | 29.24% Space Free | Partition Type: FAT32
Drive F: | 29.99 Gb Total Space | 9.03 Gb Free Space | 30.12% Space Free | Partition Type: FAT32
Drive G: | 49.02 Gb Total Space | 12.03 Gb Free Space | 24.53% Space Free | Partition Type: FAT32
Drive J: | 7.59 Gb Total Space | 1.16 Gb Free Space | 15.32% Space Free | Partition Type: FAT32

Computer Name: NIANOOR-PC | User Name: Nianoor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nianoor\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Nianoor\AppData\Local\Temp\MMBPlayer\Keychanger.exe (MRT www.Win2Farsi.com)
PRC - C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files\AutorunRemover\AutorunRemover.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe ()
PRC - D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe (PacketVideo)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Nianoor\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Internet Download Manager\idmmkb.dll (Tonec Inc.)


========== Win32 Services (SafeList) ==========

SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TwonkyMedia) – D:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe (PacketVideo)
SRV - (ServiceLayer) – D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV - (IDMWFP) – C:\Windows\System32\drivers\idmwfp.sys (Tonec Inc.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\system32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\system32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\system32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdW73.sys (ATI Technologies, Inc.)
DRV - (Aspi32) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (MTsensor) – C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (SrvHsfPCI) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\System32\drivers\L1E62x86.sys (Atheros Communications, Inc.)
DRV - (tap0901) – C:\Windows\System32\drivers\tap0901.sys (The OpenVPN Project)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (PAC207) – C:\Windows\System32\drivers\PFC027.SYS (PixArt Imaging Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 01 C0 23 CD 3D 2B CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "DVDVideoSoftTB Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/04 00:15:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Nianoor\AppData\Roaming\IDM\idmmzcc3 [2011/06/15 11:10:14 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\Nianoor\AppData\Roaming\IDM\idmmzcc3 [2011/06/15 11:10:14 | 000,000,000 | —D | M]

[2011/06/15 02:38:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Nianoor\AppData\Roaming\Mozilla\Extensions
[2011/07/12 20:18:42 | 000,000,000 | —D | M] (No name found) – C:\Users\Nianoor\AppData\Roaming\Mozilla\Firefox\Profiles\56p4kdyc.default\extensions
[2011/06/28 18:04:38 | 000,000,000 | —D | M] (DVDVideoSoftTB Community Toolbar) – C:\Users\Nianoor\AppData\Roaming\Mozilla\Firefox\Profiles\56p4kdyc.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011/06/19 13:58:11 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Nianoor\AppData\Roaming\Mozilla\Firefox\Profiles\56p4kdyc.default\extensions\[removed]
[2011/07/12 09:48:05 | 000,002,573 | —- | M] () – C:\Users\Nianoor\AppData\Roaming\Mozilla\Firefox\Profiles\56p4kdyc.default\searchplugins\askcom.xml
[2011/05/25 16:16:30 | 000,000,931 | —- | M] () – C:\Users\Nianoor\AppData\Roaming\Mozilla\Firefox\Profiles\56p4kdyc.default\searchplugins\conduit.xml
[2011/07/24 00:37:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/07/24 00:37:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/06/27 20:39:20 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/01/25 22:40:58 | 000,003,361 | RH– | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 53 more lines…
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AutorunRemover.exe] C:\Program Files\AutorunRemover\AutorunRemover.exe ()
O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [MRTKBDFA] C:\Windows\KeyChangerMRT.exe (MRT www.Win2Farsi.com)
O4 - HKLM..\Run: [NeroFilterCheck] File not found
O4 - HKLM..\Run: [openvpn-gui] C:\Program Files\UltraVPN\bin\openvpn-gui.exe ()
O4 - HKCU..\Run: [8DDYX0ZBPZ] File not found
O4 - HKCU..\Run: [BeyluxeMessenger] C:\Program Files\Beyluxe Messenger\Beyluxe Messenger.exe ()
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.EXE (Tonec Inc.)
O4 - HKCU..\Run: [L4i Messenger!] File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MsnMsgr] File not found
O4 - HKCU..\Run: [Nimbuzz] C:\Program Files\Nimbuzz\Nimbuzz.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableQuickReboot = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ehow.com ([www] http in Local intranet)
O15 - HKCU\..Trusted Domains: keep-tube.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: videodownloadx.com ([www] http in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/24 15:32:46 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\Nianoor\Desktop\OTL.exe
[2011/07/24 14:48:20 | 000,292,352 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\Cbakoa.exe
[2011/07/24 14:39:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MP4 Video Converter
[2011/07/24 14:39:41 | 000,258,048 | —- | C] (Peter Wimmer, Gabest) – C:\Windows\System32\GplMpgDec.ax
[2011/07/24 14:39:40 | 000,000,000 | —D | C] – C:\Program Files\Ultra MP4 Video Converter
[2011/07/24 10:03:59 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\COMODO
[2011/07/24 10:03:24 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2011/07/24 02:31:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
[2011/07/24 02:30:58 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UltraVPN
[2011/07/24 02:30:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraVPN
[2011/07/24 02:30:58 | 000,000,000 | —D | C] – C:\Program Files\UltraVPN
[2011/07/24 00:44:14 | 000,000,000 | —D | C] – C:\Windows\Sun
[2011/07/24 00:37:43 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/07/24 00:37:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/07/24 00:37:31 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/07/24 00:37:31 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/07/24 00:37:31 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/07/24 00:37:31 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/07/24 00:37:27 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/07/22 13:59:26 | 000,045,056 | —- | C] (Adaptec) – C:\Windows\System32\WNASPI32.DLL
[2011/07/22 13:59:26 | 000,016,512 | —- | C] (Adaptec) – C:\Windows\System32\drivers\ASPI32.SYS
[2011/07/13 22:41:52 | 000,000,000 | —D | C] – C:\Users\Nianoor\Documents\Nimbuzz Received Files
[2011/07/12 20:15:31 | 000,106,496 | —- | C] (Pegasus Software) – C:\Windows\System32\TwnLib20.dll
[2011/07/12 20:15:27 | 001,568,768 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\System32\ImagX7.dll
[2011/07/12 20:15:27 | 000,476,320 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\System32\ImagXpr7.dll
[2011/07/12 20:15:27 | 000,471,040 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\System32\ImagXRA7.dll
[2011/07/12 20:15:27 | 000,262,144 | —- | C] (Pegasus Imaging Corp.) – C:\Windows\System32\ImagXR7.dll
[2011/07/12 20:15:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2011/07/12 20:15:21 | 000,000,000 | —D | C] – C:\Program Files\Ahead
[2011/07/12 01:16:20 | 000,000,000 | —D | C] – C:\Program Files\L4i
[2011/07/12 00:16:41 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Local\nimbuzz
[2011/07/12 00:16:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nimbuzz
[2011/07/12 00:16:37 | 000,000,000 | —D | C] – C:\Program Files\Nimbuzz
[2011/07/09 21:13:09 | 000,000,000 | —D | C] – C:\Users\Nianoor\Downloads
[2011/07/09 04:46:50 | 000,000,000 | —D | C] – C:\Program Files\Text2PDF v1.5
[2011/07/09 04:46:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Text To PDF Converter v1.5
[2011/07/08 06:34:58 | 000,000,000 | —D | C] – C:\Users\Nianoor\Desktop\bey folder
[2011/07/07 23:06:06 | 000,000,000 | —D | C] – C:\Users\Nianoor\Desktop\New folder
[2011/07/06 17:36:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-PDF To Text Converter v2.1
[2011/07/06 17:36:32 | 000,000,000 | —D | C] – C:\Program Files\e-PDF To Text Converter v2.1
[2011/07/06 17:20:35 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\GetRightToGo
[2011/07/06 13:57:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Tools
[2011/07/06 13:40:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF to Word
[2011/07/06 13:40:15 | 000,000,000 | —D | C] – C:\Program Files\PDF to Word
[2011/07/05 23:09:51 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Regensoft
[2011/07/05 23:08:22 | 000,000,000 | —D | C] – C:\Users\Nianoor\Documents\Red Kawa
[2011/07/05 23:08:22 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Red Kawa
[2011/07/05 23:02:05 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Local\Geckofx
[2011/07/05 23:01:42 | 000,000,000 | —D | C] – C:\Users\Nianoor\Documents\Regensoft
[2011/07/05 23:01:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Regensoft
[2011/07/05 23:01:42 | 000,000,000 | —D | C] – C:\Program Files\Regensoft
[2011/07/05 23:01:41 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2011/07/05 23:01:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2011/07/05 23:01:40 | 000,000,000 | —D | C] – C:\Program Files\AviSynth 2.5
[2011/07/05 23:01:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Kawa
[2011/07/05 23:01:33 | 000,000,000 | —D | C] – C:\Program Files\Red Kawa
[2011/07/04 00:16:46 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Apple Computer
[2011/07/04 00:16:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/07/04 00:16:40 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2011/07/04 00:16:16 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/07/04 00:16:15 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/07/04 00:16:15 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/07/04 00:15:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/07/04 00:15:34 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/04 00:15:34 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/07/04 00:15:22 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/07/04 00:15:01 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/07/04 00:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/07/04 00:14:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/07/03 05:58:30 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Local\Windows Live
[2011/07/03 05:58:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/06/30 19:29:41 | 000,000,000 | —D | C] – C:\Users\Nianoor\AppData\Roaming\Real
[2011/06/28 18:01:02 | 000,000,000 | —D | C] – C:\Program Files\MSECache
========== Files - Modified Within 30 Days ==========

[2011/07/24 15:33:29 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Nianoor\Desktop\OTL.exe
[2011/07/24 15:27:03 | 000,000,294 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/07/24 15:18:03 | 000,000,294 | -H– | M] () – C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
[2011/07/24 15:00:29 | 000,003,584 | —- | M] () – C:\Users\Nianoor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/24 15:00:27 | 000,000,147 | —- | M] () – C:\Windows\System32\test.aok
[2011/07/24 15:00:19 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/07/24 14:48:13 | 000,292,352 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\Cbakoa.exe
[2011/07/24 14:48:09 | 000,000,314 | RHS- | M] () – C:\Windows\tasks\ijgqkvuidg.job
[2011/07/24 14:48:03 | 000,064,512 | RHS- | M] () – C:\Windows\System32\rasautouv.dll
[2011/07/24 14:39:42 | 000,001,087 | —- | M] () – C:\Users\Nianoor\Desktop\Ultra MP4 Video Converter.lnk
[2011/07/24 14:31:10 | 000,000,600 | —- | M] () – C:\Users\Nianoor\PUTTY.RND
[2011/07/24 09:27:43 | 000,021,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/24 09:27:43 | 000,021,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/24 09:24:31 | 000,615,122 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/07/24 09:24:31 | 000,103,496 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/07/24 09:20:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/24 09:20:02 | 1609,916,416 | -HS- | M] () – C:\hiberfil.sys
[2011/07/24 02:30:59 | 000,001,080 | —- | M] () – C:\Users\Nianoor\Desktop\UltraVPN.lnk
[2011/07/24 01:06:54 | 002,166,345 | —- | M] () – C:\Users\Nianoor\Desktop\Breaking Dawn Comic Con Panel #2 - Robert Pattinson, Kristen Stewart, Taylor Lautner [Keep-Mp3.com].mp3
[2011/07/24 00:37:28 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/07/24 00:37:28 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/07/24 00:37:28 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/07/24 00:37:28 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/07/23 20:32:56 | 000,001,393 | —- | M] () – C:\Users\Public\Desktop\Internet Explorer.lnk
[2011/07/20 09:22:04 | 000,351,520 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/17 22:49:21 | 000,579,725 | —- | M] () – C:\Users\Nianoor\Desktop\sina.jpg
[2011/07/12 20:37:15 | 000,000,151 | —- | M] () – C:\Users\Nianoor\AppData\Roaming\burnaware.ini
[2011/07/12 00:16:39 | 000,000,953 | —- | M] () – C:\Users\Public\Desktop\Nimbuzz.lnk
[2011/07/10 06:11:15 | 377,077,070 | —- | M] () – C:\Users\Nianoor\Desktop\IMG_0456.MOV
[2011/07/09 04:46:50 | 000,000,961 | —- | M] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\Text To PDF Converter v1.5.lnk
[2011/07/08 06:44:31 | 000,031,249 | —- | M] () – C:\Users\Nianoor\Desktop\22082009.mp4
[2011/07/07 03:08:29 | 000,347,361 | —- | M] () – C:\Users\Nianoor\Desktop\m1.mp3
[2011/07/06 17:36:56 | 000,001,024 | —- | M] () – C:\Windows\System32\pdftotext.dat
[2011/07/06 17:36:56 | 000,001,024 | —- | M] () – C:\Windows\System32\e-pdfcreator.dat
[2011/07/06 13:57:14 | 000,000,918 | —- | M] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\PDF Editor.lnk
[2011/07/06 13:40:16 | 000,001,000 | —- | M] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\PDF to Word.lnk
[2011/07/06 13:40:16 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\PDF to Word.lnk
[2011/07/06 13:18:23 | 000,079,518 | —- | M] () – C:\Users\Nianoor\Desktop\winnie_the_pooh-1132.jpg
[2011/07/05 23:01:42 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\YouTube Downloader App.lnk
[2011/07/05 23:01:33 | 000,002,156 | —- | M] () – C:\Users\Public\Desktop\Videora iPod Converter.lnk
[2011/07/05 18:09:11 | 000,005,939 | —- | M] () – C:\Users\Nianoor\Desktop\images.jpg
[2011/07/05 17:56:18 | 000,469,847 | —- | M] () – C:\Users\Nianoor\Desktop\sadness_elima_sub_ir%20(13).gif
[2011/07/05 17:30:53 | 000,011,549 | —- | M] () – C:\Users\Nianoor\Desktop\heart.jpg
[2011/07/04 00:16:42 | 000,001,753 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/07/04 00:15:41 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/07/03 07:46:30 | 000,021,098 | —- | M] () – C:\Users\Nianoor\Desktop\32gb_ipod_touch.jpg
[2011/07/02 03:01:32 | 000,048,990 | —- | M] () – C:\Users\Nianoor\Desktop\20100701_011.jpg
[2011/07/02 03:00:10 | 000,033,659 | —- | M] () – C:\Users\Nianoor\Desktop\20100128_033.jpg
[2011/06/29 04:43:18 | 000,028,945 | —- | M] () – C:\Users\Nianoor\Desktop\4dca9b858493cb7894db1e2d00fe1956.jpg
[2011/06/27 19:59:38 | 000,002,696 | —- | M] () – C:\Users\Public\Desktop\Activation Winse7en.lnk
[2011/06/25 13:16:49 | 000,123,608 | —- | M] () – C:\Users\Nianoor\Desktop\bestfullsc_319xrjce.sisx
[2011/06/25 13:14:39 | 000,560,628 | —- | M] () – C:\Users\Nianoor\Desktop\sms20forno_yk981coj.sis
[2011/06/25 09:27:14 | 000,115,240 | —- | M] () – C:\Users\Nianoor\Desktop\mumsmsjk_udq9t4fu.sis
[2011/06/24 18:21:50 | 000,007,602 | —- | M] () – C:\Users\Nianoor\AppData\Local\resmon.resmoncfg

========== Files Created - No Company Name ==========

[2011/07/24 15:00:29 | 000,003,584 | —- | C] () – C:\Users\Nianoor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/24 15:00:17 | 000,000,147 | —- | C] () – C:\Windows\System32\test.aok
[2011/07/24 14:48:33 | 000,000,294 | -H– | C] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/07/24 14:48:15 | 000,000,294 | -H– | C] () – C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
[2011/07/24 14:48:04 | 000,000,314 | RHS- | C] () – C:\Windows\tasks\ijgqkvuidg.job
[2011/07/24 14:48:03 | 000,064,512 | RHS- | C] () – C:\Windows\System32\rasautouv.dll
[2011/07/24 14:39:42 | 000,001,087 | —- | C] () – C:\Users\Nianoor\Desktop\Ultra MP4 Video Converter.lnk
[2011/07/24 14:39:40 | 000,129,024 | —- | C] () – C:\Windows\System32\AVERM.dll
[2011/07/24 14:39:40 | 000,028,672 | —- | C] () – C:\Windows\System32\AVEQT.dll
[2011/07/24 02:30:59 | 000,001,080 | —- | C] () – C:\Users\Nianoor\Desktop\UltraVPN.lnk
[2011/07/24 00:56:58 | 002,166,345 | —- | C] () – C:\Users\Nianoor\Desktop\Breaking Dawn Comic Con Panel #2 - Robert Pattinson, Kristen Stewart, Taylor Lautner [Keep-Mp3.com].mp3
[2011/07/21 19:17:47 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2011/07/17 22:49:21 | 000,579,725 | —- | C] () – C:\Users\Nianoor\Desktop\sina.jpg
[2011/07/17 22:47:20 | 000,759,433 | —- | C] () – C:\Users\Nianoor\Desktop\DSC02025.JPG
[2011/07/13 03:10:42 | 020,127,132 | —- | C] () – C:\Users\Nianoor\Desktop\12 - Revolution 9.mp3
[2011/07/12 20:37:13 | 000,000,151 | —- | C] () – C:\Users\Nianoor\AppData\Roaming\burnaware.ini
[2011/07/12 00:16:39 | 000,000,953 | —- | C] () – C:\Users\Public\Desktop\Nimbuzz.lnk
[2011/07/10 07:20:16 | 377,077,070 | —- | C] () – C:\Users\Nianoor\Desktop\IMG_0456.MOV
[2011/07/09 04:46:50 | 000,000,961 | —- | C] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\Text To PDF Converter v1.5.lnk
[2011/07/08 06:44:31 | 000,031,249 | —- | C] () – C:\Users\Nianoor\Desktop\22082009.mp4
[2011/07/07 03:07:58 | 000,347,361 | —- | C] () – C:\Users\Nianoor\Desktop\m1.mp3
[2011/07/06 17:36:56 | 000,001,024 | —- | C] () – C:\Windows\System32\pdftotext.dat
[2011/07/06 17:36:56 | 000,001,024 | —- | C] () – C:\Windows\System32\e-pdfcreator.dat
[2011/07/06 16:59:20 | 003,868,639 | —- | C] () – C:\Users\Nianoor\Desktop\Coolio - Gangster's Paradise.mp3
[2011/07/06 13:57:14 | 000,000,918 | —- | C] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\PDF Editor.lnk
[2011/07/06 13:40:16 | 000,001,000 | —- | C] () – C:\Users\Nianoor\Application Data\Microsoft\Internet Explorer\Quick Launch\PDF to Word.lnk
[2011/07/06 13:40:16 | 000,000,976 | —- | C] () – C:\Users\Public\Desktop\PDF to Word.lnk
[2011/07/06 13:18:18 | 000,079,518 | —- | C] () – C:\Users\Nianoor\Desktop\winnie_the_pooh-1132.jpg
[2011/07/05 23:01:42 | 000,002,100 | —- | C] () – C:\Users\Public\Desktop\YouTube Downloader App.lnk
[2011/07/05 23:01:33 | 000,002,156 | —- | C] () – C:\Users\Public\Desktop\Videora iPod Converter.lnk
[2011/07/05 18:09:10 | 000,005,939 | —- | C] () – C:\Users\Nianoor\Desktop\images.jpg
[2011/07/05 17:56:17 | 000,469,847 | —- | C] () – C:\Users\Nianoor\Desktop\sadness_elima_sub_ir%20(13).gif
[2011/07/05 17:30:52 | 000,011,549 | —- | C] () – C:\Users\Nianoor\Desktop\heart.jpg
[2011/07/04 00:16:42 | 000,001,753 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/07/04 00:15:41 | 000,001,815 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/07/04 00:15:23 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/07/03 07:46:28 | 000,021,098 | —- | C] () – C:\Users\Nianoor\Desktop\32gb_ipod_touch.jpg
[2011/07/02 03:02:43 | 000,048,990 | —- | C] () – C:\Users\Nianoor\Desktop\20100701_011.jpg
[2011/07/02 03:01:12 | 000,033,659 | —- | C] () – C:\Users\Nianoor\Desktop\20100128_033.jpg
[2011/06/29 04:44:05 | 000,028,945 | —- | C] () – C:\Users\Nianoor\Desktop\4dca9b858493cb7894db1e2d00fe1956.jpg
[2011/06/25 13:16:45 | 000,123,608 | —- | C] () – C:\Users\Nianoor\Desktop\bestfullsc_319xrjce.sisx
[2011/06/25 13:14:25 | 000,560,628 | —- | C] () – C:\Users\Nianoor\Desktop\sms20forno_yk981coj.sis
[2011/06/25 09:27:12 | 000,115,240 | —- | C] () – C:\Users\Nianoor\Desktop\mumsmsjk_udq9t4fu.sis
[2011/06/15 02:56:48 | 000,007,602 | —- | C] () – C:\Users\Nianoor\AppData\Local\resmon.resmoncfg
[2011/06/15 02:50:50 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/06/15 02:38:36 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/06/15 02:37:46 | 000,002,888 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/06/15 02:31:42 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/06/15 02:31:40 | 000,019,286 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2011/06/15 02:16:26 | 002,362,368 | —- | C] () – C:\Windows\PDFReader.exe
[2011/06/15 02:16:26 | 000,716,122 | —- | C] () – C:\Windows\unins000.exe
[2011/06/15 02:16:26 | 000,002,027 | —- | C] () – C:\Windows\unins000.dat
[2011/06/15 02:16:22 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/06/15 02:16:22 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/06/15 02:16:21 | 000,810,496 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/06/15 02:16:21 | 000,183,808 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/06/15 02:16:21 | 000,080,896 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/20 14:29:34 | 000,100,864 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/20 14:29:26 | 000,086,016 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2010/09/22 11:27:52 | 000,223,990 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/07/15 20:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/13 21:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,351,520 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,615,122 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,103,496 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 05:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2006/11/02 09:27:46 | 000,000,518 | —- | C] () – C:\Windows\System32\SP207.INI
[2004/01/08 10:30:22 | 000,011,170 | —- | C] () – C:\Windows\System32\PA207USD.DLL

========== LOP Check ==========

[2011/06/24 07:53:30 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Babylon
[2011/07/15 08:38:52 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Beyluxe
[2011/07/24 14:52:51 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\DMCache
[2011/06/18 22:36:34 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\DVDVideoSoft
[2011/06/18 22:15:22 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/07/06 17:21:10 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\GetRightToGo
[2011/07/22 03:33:10 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\IDM
[2011/06/15 02:51:29 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\ManyCam
[2011/06/22 02:17:22 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\muvee Technologies
[2011/06/22 02:21:23 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Nokia
[2011/06/22 02:13:25 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Nseries
[2011/06/22 02:00:16 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\PC Suite
[2011/07/05 23:08:22 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Red Kawa
[2011/07/05 23:09:51 | 000,000,000 | —D | M] – C:\Users\Nianoor\AppData\Roaming\Regensoft
[2011/07/24 14:48:09 | 000,000,314 | RHS- | M] () – C:\Windows\Tasks\ijgqkvuidg.job
[2009/07/13 21:53:46 | 000,026,872 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/07/24 15:27:03 | 000,000,294 | -H– | M] () – C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/07/24 15:18:03 | 000,000,294 | -H– | M] () – C:\Windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 14:29:06 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/06/15 03:09:33 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/07/24 09:20:02 | 1609,916,416 | -HS- | M] () – C:\hiberfil.sys
[2011/06/15 02:46:52 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/06/15 02:46:52 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/06/15 02:19:12 | 000,351,297 | RHS- | M] () – C:\OJVWB
[2011/07/24 09:20:09 | 2146,557,952 | -HS- | M] () – C:\pagefile.sys
[2011/06/15 02:19:13 | 000,000,020 | RHS- | M] () – C:\win7.ld

< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 18:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 14:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/02/21 06:02:14 | 000,126,976 | —- | M] () – C:\Windows\Dream Aquarium.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/13 21:46:35 | 000,000,442 | -HS- | M] () – C:\ProgramData\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/15 02:22:39 | 000,000,221 | -HS- | M] () – C:\Users\Nianoor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/15 13:21:08 | 000,245,760 | —- | M] (My Beyluxe ID: ll.HAMID.ll) – C:\Users\Nianoor\Desktop\Beyluxe Heart Smiles 1.3(2).exe
[2011/06/15 14:43:55 | 000,318,464 | —- | M] () – C:\Users\Nianoor\Desktop\Beyluxe New Icons(Windows 7 Version 2)-WwW.Bandari.iR.exe
[2011/07/24 15:33:29 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\Nianoor\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
OTL Extras logfile created on: 7/24/2011 3:36:47 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Nianoor\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 66.20% Memory free
4.00 Gb Paging File | 3.27 Gb Available in Paging File | 81.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 20.00 Gb Total Space | 4.39 Gb Free Space | 21.94% Space Free | Partition Type: NTFS
Drive D: | 20.00 Gb Total Space | 11.10 Gb Free Space | 55.52% Space Free | Partition Type: NTFS
Drive E: | 29.99 Gb Total Space | 8.77 Gb Free Space | 29.24% Space Free | Partition Type: FAT32
Drive F: | 29.99 Gb Total Space | 9.03 Gb Free Space | 30.12% Space Free | Partition Type: FAT32
Drive G: | 49.02 Gb Total Space | 12.03 Gb Free Space | 24.53% Space Free | Partition Type: FAT32
Drive J: | 7.59 Gb Total Space | 1.16 Gb Free Space | 15.32% Space Free | Partition Type: FAT32

Computer Name: NIANOOR-PC | User Name: Nianoor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"UacDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{016BE60E-27DD-4AD0-814C-3A1C3C0A0B68}" = SMC ADSL2 Barricade
"{0C42FE26-F225-B4AF-B6C5-1CFFF3076A9F}" = ATI AVIVO Codecs
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20B9BC7F-BB40-4A4F-95D6-91E4D8FBE5AF}" = PC CameraN
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{32D67656-20CD-8C6C-7CC4-E345AC059CDE}" = AMD Drag and Drop Transcoding
"{3F54B9C1-16A6-B1CC-ADB3-81C4CE3E1D18}" = ATI Catalyst Install Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{67EFADAD-D448-CF11-4785-BF7F95D1980B}" = Catalyst Control Center InstallProxy
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{9C7C8898-DC29-4E8B-9E77-55A77C3250F6}" = PC Connectivity Solution
"{A0C32A95-848F-73FD-ACFC-C66EF566B91B}" = HydraVision
"{A4E0CA0F-1903-440A-9B98-FEA6CB049999}" = Nokia Flashing Cable Driver
"{AA1D2BF3-E347-7232-119A-7F62DD4901B3}" = WMV9/VC-1 Video Playback
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}" = Nokia Connectivity Cable Driver
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{DAC63ECB-4571-435F-9B19-51F54BC88109}" = Nokia Home Media Server
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AviSynth" = AviSynth 2.5
"Beyluxe Messenger1" = Beyluxe Messenger
"e-PDF To Text Converter v2.1_is1" = e-PDF To Text Converter v2.1
"InstallShield_{20B9BC7F-BB40-4A4F-95D6-91E4D8FBE5AF}" = PC CameraN
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.7.0
"Mozilla Firefox 5.0 (x86 en-US)" = Mozilla Firefox 5.0 (x86 en-US)
"Nimbuzz" = Nimbuzz 1.1.1
"OpenVPN" = UltraVPN
"RealAlt_is1" = Real Alternative 2.0.2
"Text To PDF Converter v1.5_is1" = Text To PDF Converter v1.5
"The KMPlayer" = The KMPlayer (remove only)
"Ultra MP4 Video Converter_is1" = Ultra MP4 Video Converter 4.3.0409
"Uninstall_is1" = Uninstall 1.0.0.1
"Videora iPod Converter" = Videora iPod Converter 6
"Windows Se7en(Farsi Fonts -Nastaliq-Keyboard)_is1" = Windows Se7en Fonts
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"YouTube Downloader App" = YouTube Downloader App 3.00

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/23/2011 12:05:25 AM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/23/2011 3:21:25 AM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/23/2011 11:52:39 AM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/23/2011 2:56:21 PM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/23/2011 9:12:47 PM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/24/2011 12:37:50 AM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/24/2011 12:21:53 PM | Computer Name = Nianoor-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/24/2011 4:57:09 PM | Computer Name = Nianoor-PC | Source = Application Hang | ID = 1002
Description = The program wmplayer.exe version 12.0.7601.17514 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 7c8 Start
Time: 01cc4a4243cb0801 Termination Time: 22 Application Path: C:\Program Files\Windows
Media Player\wmplayer.exe Report Id: 7a5e9df4-b637-11e0-a2ec-e0cb4e4abd6d

Error - 7/24/2011 6:15:14 PM | Computer Name = Nianoor-PC | Source = Windows Search Service | ID = 1019
Description =

Error - 7/24/2011 6:15:15 PM | Computer Name = Nianoor-PC | Source = Windows Search Service | ID = 1019
Description =

[ System Events ]
Error - 7/17/2011 3:57:24 AM | Computer Name = Nianoor-PC | Source = Microsoft-Windows-Time-Service | ID = 34
Description = The time service has detected that the system time needs to be changed
by -127846 seconds. The time service will not change the system time by more than
54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->65.55.56.40:123) is working
properly.

Error - 7/17/2011 9:22:04 PM | Computer Name = Nianoor-PC | Source = Service Control Manager | ID = 7034
Description = The TwonkyMedia service terminated unexpectedly. It has done this
1 time(s).

Error - 7/20/2011 6:21:45 AM | Computer Name = Nianoor-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 7/21/2011 4:44:29 PM | Computer Name = Nianoor-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 7/21/2011 4:49:24 PM | Computer Name = Nianoor-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 7/21/2011 10:09:24 PM | Computer Name = Nianoor-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 7/21/2011 10:09:32 PM | Computer Name = Nianoor-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 7/21/2011 10:18:48 PM | Computer Name = Nianoor-PC | Source = Service Control Manager | ID = 7034
Description = The TwonkyMedia service terminated unexpectedly. It has done this
1 time(s).

Error - 7/24/2011 5:31:33 AM | Computer Name = Nianoor-PC | Source = Microsoft-Windows-Time-Service | ID = 34
Description = The time service has detected that the system time needs to be changed
by -127841 seconds. The time service will not change the system time by more than
54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->65.55.56.40:123) is working
properly.

Error - 7/24/2011 1:04:11 PM | Computer Name = Nianoor-PC | Source = Service Control Manager | ID = 7030
Description = The COMODO EasyVPN VNC Service service is marked as an interactive
service. However, the system is configured to not allow interactive services.
This service may not function properly.


< End of report >
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI