This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Error 0xc0000142 [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys :) I have a Dell laptop, and it's been working fine up until yesterday, when it started popping up a message saying that it couldn't start programs due to error 0xc0000142. When I start the laptop, it pops up about every program on startup. I have tried to download a registry cleaner, but I didn't think that one through, as it won't let me open it!! Any help you could give would be much appreciated :) Lisa
Hello Delphiansoul and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Before checking to see if this is a malware issue, let’s try to restore your system to a previous state.
  • go to Start - All Programs - Accessories - System Tools - System Restore. or press the WinKey on the keyboard, type Restore then press enter.
  • press continue at the “Windows needs you permission to continue dialog box.
  • select “Choose a different Restore Point” and choose a date when your computer was working well then press Next
  • click on Yes to continue
  • the system will reboot and a dialog box will appear informing you if the restore was successful.
============================

If the programs still won’t run, try running them in safe mode

To start in safe mode:
  • restart your computer.
  • when the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows Advanced Boot Options menu
  • select the option for Safe Mode using the arrow keys
  • then press Enter on your keyboard to boot into Safe Mode.
You should then be presented with the Windows Login screen. Log in to Windows and see if you can now run your programs.

Satchfan
Hi satchfan, thanks for your reply :) I have tried doing a restore, but it says there's no restore point. It is a fairly new laptop. Thanks :)
As you can run programs in safe mode, please try to download and run the following scans so that we can see what is happening.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

• disable any script blocking protection (How to Disable your Security Programs)
• double click DDS icon to run the tool (may take up to 3 minutes to run)
• when done, DDS.txt will open.
• after a few moments, attach.txt will open in a second window.
• save both reports to your desktop.
• Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

DDS.txt
Attach.txt
aswMBR log


Satchfan
Hi Delphiansoul

You do have an infected computer so we have some work to do. ;)

Run RogueKiller

Note: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when prompted, type 1 and press Enter
  • the RKreport.txt will be generated next to the executable, (on the desktop).
    If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.

Remember: do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
Thanks

Satchfan
Run ExeHelper

Please download exeHelper by Raktor to your desktop.• Double-click on exeHelper.com to run the fix
• A black window should pop up; press any key to close it once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)

===================================================

Download and run OTL

Please try running this in normal mode. If you are unable to, then use safe mode.
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Logs to include with next post:

exehelperlog.txt
OTL.txt
Extras.txt


Thanks

Satchfan
OTL logfile created on: 10/01/2012 18:17:50 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Daughtry\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.25 Gb Available Physical Memory | 81.44% Memory free
7.99 Gb Paging File | 7.29 Gb Available in Paging File | 91.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 58.59 Gb Total Space | 12.19 Gb Free Space | 20.81% Space Free | Partition Type: NTFS
Drive D: | 229.63 Gb Total Space | 227.29 Gb Free Space | 98.98% Space Free | Partition Type: NTFS
Drive R: | 9.77 Gb Total Space | 4.32 Gb Free Space | 44.26% Space Free | Partition Type: NTFS

Computer Name: DAUGHTRY-PC | User Name: Daughtry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Daughtry\Downloads\OTL.exe (OldTimer Tools)


========== Modules (No Company Name) ==========

MOD - C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll ()
MOD - C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\avutil-51.dll ()
MOD - C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\avformat-53.dll ()
MOD - C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\avcodec-53.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (btwdins) – c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (HssTrayService) – C:\Program Files (x86)\Hotspot Shield\bin\HSSTrayService.exe ()
SRV - (hshld) – C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (PassThru Service) – C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (PCToolsFirewallPlus) – C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe (PC Tools)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WAS) – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AcfXAudioService) – C:\Windows\SysWOW64\ACFXAU64.dll (Conexant Systems, Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
SRV - (AOL ACS) – C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)


========== Driver Services (SafeList) ==========

DRV:64bit: - (HssDrv) – C:\Windows\SysNative\drivers\HssDrv.sys (AnchorFree Inc.)
DRV:64bit: - (taphss) – C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (pctplfw) – C:\Windows\SysNative\drivers\pctplfw64.sys (PC Tools)
DRV:64bit: - (PCTFW-PacketFilter) – C:\Windows\SysNative\drivers\pctNdis-PacketFilter64.sys (PC Tools)
DRV:64bit: - (pctgntdi) – C:\Windows\SysNative\drivers\pctgntdi64.sys (PC Tools)
DRV:64bit: - (pctNdisMP) – C:\Windows\SysNative\drivers\pctNdis64.sys (PC Tools)
DRV:64bit: - (pctNdis) – C:\Windows\SysNative\drivers\pctNdis64.sys (PC Tools)
DRV:64bit: - (htcnprot) – C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\ACFXAU64.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\ACFSDK64.sys (Conexant)
DRV:64bit: - (wanatw) WAN Miniport (ATW) – C:\Windows\SysNative\drivers\wanatw64.sys (America Online, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@gametap.com/npdd,version=1.0: C:\Program Files (x86)\Downloader\npdd.dll (Metaboli)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Daughtry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Daughtry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: C:\Program Files (x86)\PriceGong\2.5.0\FF [2011/12/02 02:00:54 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Linkury Smartbar Search (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search? p={searchTerms}&ei=UTF-8&fr=w3is&type=
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Daughtry\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Downloader Detector (Enabled) = C:\Program Files (x86)\Downloader\npdd.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Daughtry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Community Smartbar = C:\Users\Daughtry\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\
CHR - Extension: YouTube = C:\Users\Daughtry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Users\Daughtry\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: ProfileSong = C:\Users\Daughtry\AppData\Local\Google\Chrome\User Data\Default\Extensions\llempgdfimeebjiidmafcjpnlfnpnknj\2.3.2.4_0\
CHR - Extension: Gmail = C:\Users\Daughtry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc)
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [00PCTFW] C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1310775415\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKCU..\Run: [EPSON S21 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFAE.EXE /FU "C:\Windows\TEMP\E_S930C.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [Linkury Chrome Smartbar] C:\Program Files (x86)\Linkury\Linkury.exe (Linkury)
O4 - Startup: C:\Users\Daughtry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Daughtry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Daughtry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Daughtry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5B4F2989-A9B9-42EE-A95E-CC383A9E18C4}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BDC43EB9-8CA2-4AE4-A36E-735BDD3473FB}: NameServer = 10.2.64.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D6F5B700-3FF2-41D5-A92C-0C8CD481DE17}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2012/01/10 12:41:48 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\RK_Quarantine
[2012/01/08 13:16:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/01/08 13:16:39 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/01/08 02:42:38 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2012/01/08 02:35:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
[2012/01/08 02:35:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
[2012/01/08 02:35:08 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Local\PackageAware
[2012/01/08 02:28:10 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\FreeFileViewer
[2012/01/08 02:27:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2012/01/08 02:27:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2012/01/08 02:27:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2012/01/08 02:27:17 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Local\Linkury
[2012/01/08 02:27:17 | 000,000,000 | —D | C] – C:\ProgramData\Linkury
[2012/01/08 02:27:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Linkury
[2012/01/08 02:27:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2012/01/08 02:21:52 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\New folder (2)
[2012/01/08 01:11:10 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\Tubes
[2012/01/08 01:10:17 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\Betty
[2012/01/08 00:04:54 | 000,000,000 | —D | C] – C:\Program Files\Digital Dominion
[2012/01/08 00:01:11 | 000,091,648 | R— | C] (Preview Software Inc) – C:\Windows\tl32v20.dll
[2012/01/07 23:58:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaCreations
[2012/01/07 14:59:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extensis
[2012/01/07 14:59:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Extensis
[2012/01/07 14:38:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plugin Commander Light
[2012/01/07 14:38:46 | 001,355,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSVBVM50.DLL
[2012/01/07 14:38:46 | 001,081,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mscomctl.ocx
[2012/01/07 14:38:46 | 000,304,640 | —- | C] (Data Techniques, Inc.) – C:\Windows\SysWow64\imgman32.dll
[2012/01/07 14:38:46 | 000,152,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Comdlg32.ocx
[2012/01/07 14:38:46 | 000,067,072 | —- | C] (Data Techniques, Inc.) – C:\Windows\SysWow64\IM31jpg.dil
[2012/01/07 14:38:46 | 000,059,392 | —- | C] (Data Techniques, Inc.) – C:\Windows\SysWow64\imhost32.dll
[2012/01/07 14:38:46 | 000,035,840 | —- | C] (Data Techniques, Inc.) – C:\Windows\SysWow64\IM31bmp.dil
[2012/01/07 14:38:46 | 000,032,256 | —- | C] (Data Techniques, Inc.) – C:\Windows\SysWow64\IM31xbmp.del
[2012/01/07 14:38:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Plugin Commander Light
[2012/01/07 14:29:13 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\Plugin Dll
[2012/01/07 13:25:16 | 000,000,000 | —D | C] – C:\ProgramData\InstallShield
[2012/01/07 13:25:13 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jasc Software
[2012/01/07 13:24:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Jasc Software Inc
[2012/01/07 13:24:12 | 000,000,000 | —D | C] – C:\Users\Daughtry\Documents\My PSP Files
[2012/01/07 13:24:12 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\Jasc Software Inc
[2012/01/07 13:24:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jasc Software Inc
[2012/01/07 01:20:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\HotSpot_International
[2012/01/07 01:19:58 | 000,000,000 | —D | C] – C:\Hotspot Shield
[2012/01/07 01:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
[2012/01/07 01:19:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hotspot Shield
[2012/01/07 00:53:53 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\New folder
[2012/01/07 00:36:53 | 000,000,000 | —D | C] – C:\ProgramData\Premium
[2012/01/07 00:36:52 | 000,000,000 | —D | C] – C:\ProgramData\InstallMate
[2012/01/05 19:13:34 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/01/05 19:13:34 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/01/05 19:13:34 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/12/30 14:19:56 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/28 23:57:30 | 000,056,832 | —- | C] (AnchorFree Inc.) – C:\Windows\SysNative\drivers\HssDrv.sys
[2011/12/28 23:57:26 | 000,037,888 | —- | C] (AnchorFree Inc) – C:\Windows\SysNative\drivers\taphss.sys
[2011/12/20 16:29:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\7-Zip
[2011/12/20 16:22:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitTorrent
[2011/12/20 16:21:22 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\BitTorrent
[2011/12/20 02:58:15 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\Serif
[2011/12/20 02:29:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\MSSoap
[2011/12/20 02:29:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif Applications
[2011/12/20 02:29:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Serif
[2011/12/16 19:56:02 | 000,000,000 | —D | C] – C:\Users\Daughtry\Desktop\stuff
[2011/12/16 19:06:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/16 19:06:11 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/16 19:06:10 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/16 19:06:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/12/14 13:41:42 | 000,000,000 | —D | C] – C:\Users\Daughtry\AppData\Roaming\Avira
[2011/12/14 13:41:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync

========== Files - Modified Within 30 Days ==========

[2012/01/10 12:39:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/10 12:39:51 | 3217,268,736 | -HS- | M] () – C:\hiberfil.sys
[2012/01/10 12:39:05 | 000,000,408 | —- | M] () – C:\Windows\tasks\FreeFileViewerUpdateChecker.job
[2012/01/10 08:01:38 | 000,000,512 | —- | M] () – C:\Users\Daughtry\Desktop\MBR.dat
[2012/01/09 15:48:37 | 000,000,180 | —- | M] () – C:\Users\Daughtry\Documents\cc_20120109_154832.reg
[2012/01/09 15:48:11 | 000,022,958 | —- | M] () – C:\Users\Daughtry\Documents\cc_20120109_154758.reg
[2012/01/09 00:15:13 | 000,013,632 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/09 00:15:13 | 000,013,632 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/08 13:24:43 | 000,132,766 | —- | M] () – C:\Users\Daughtry\Documents\cc_20120108_132434.reg
[2012/01/08 13:16:40 | 000,000,824 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/08 13:04:00 | 000,000,920 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1747492055-3932847036-1213101306-1001UA.job
[2012/01/08 02:27:37 | 000,001,109 | —- | M] () – C:\Users\Daughtry\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/01/08 02:27:37 | 000,001,085 | —- | M] () – C:\Users\Daughtry\Desktop\FreeFileViewer.lnk
[2012/01/08 02:16:05 | 004,297,102 | —- | M] () – C:\Users\Daughtry\Desktop\Alien Skin Xenofex 2.12.exe
[2012/01/08 02:12:59 | 004,286,161 | —- | M] () – C:\Users\Daughtry\Desktop\Alien Skin Xenofex 2.12.zip
[2012/01/08 02:03:12 | 000,847,856 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/08 02:03:12 | 000,715,792 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/08 02:03:12 | 000,141,712 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/07 14:31:14 | 000,032,768 | —- | M] (Adobe Systems, Inc.) – C:\Windows\plugin.dll
[2012/01/07 14:29:39 | 000,210,944 | —- | M] () – C:\Windows\MSVCRT10.DLL
[2012/01/07 13:25:13 | 000,003,093 | —- | M] () – C:\Users\Daughtry\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk
[2012/01/07 13:14:05 | 000,383,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/30 14:20:00 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/30 01:14:19 | 000,001,013 | —- | M] () – C:\Users\Daughtry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/12/28 23:57:30 | 000,056,832 | —- | M] (AnchorFree Inc.) – C:\Windows\SysNative\drivers\HssDrv.sys
[2011/12/28 23:57:26 | 000,037,888 | —- | M] (AnchorFree Inc) – C:\Windows\SysNative\drivers\taphss.sys
[2011/12/20 16:33:40 | 000,001,056 | —- | M] () – C:\prefs.js
[2011/12/14 20:04:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1747492055-3932847036-1213101306-1001Core.job

========== Files Created - No Company Name ==========

[2012/01/10 08:01:38 | 000,000,512 | —- | C] () – C:\Users\Daughtry\Desktop\MBR.dat
[2012/01/09 15:48:35 | 000,000,180 | —- | C] () – C:\Users\Daughtry\Documents\cc_20120109_154832.reg
[2012/01/09 15:48:03 | 000,022,958 | —- | C] () – C:\Users\Daughtry\Documents\cc_20120109_154758.reg
[2012/01/08 13:24:39 | 000,132,766 | —- | C] () – C:\Users\Daughtry\Documents\cc_20120108_132434.reg
[2012/01/08 13:16:40 | 000,000,824 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/08 02:27:41 | 000,000,408 | —- | C] () – C:\Windows\tasks\FreeFileViewerUpdateChecker.job
[2012/01/08 02:27:37 | 000,001,109 | —- | C] () – C:\Users\Daughtry\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/01/08 02:27:37 | 000,001,085 | —- | C] () – C:\Users\Daughtry\Desktop\FreeFileViewer.lnk
[2012/01/08 02:12:45 | 004,286,161 | —- | C] () – C:\Users\Daughtry\Desktop\Alien Skin Xenofex 2.12.zip
[2012/01/07 14:38:46 | 000,210,944 | —- | C] () – C:\Windows\SysWow64\Msvcrt10.dll
[2012/01/07 13:25:59 | 000,003,093 | —- | C] () – C:\Users\Daughtry\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk
[2012/01/07 00:59:57 | 000,002,527 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif AlbumPlus Organizer Starter Edition.lnk
[2012/01/07 00:59:57 | 000,002,507 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif PhotoPlus Starter Edition.lnk
[2011/12/20 02:29:15 | 000,002,499 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif DrawPlus Starter Edition.lnk
[2011/04/09 15:52:21 | 000,000,004 | —- | C] () – C:\Windows\msoffice.ini
[2011/04/07 10:45:52 | 000,000,335 | —- | C] () – C:\Windows\nsreg.dat
[2011/03/30 12:54:36 | 000,170,081 | —- | C] () – C:\Windows\hpoins14.dat
[2011/03/30 12:54:36 | 000,001,498 | —- | C] () – C:\Windows\hpomdl14.dat
[2011/02/17 13:32:24 | 000,000,476 | —- | C] () – C:\Users\Daughtry\AppData\Roaming\wklnhst.dat
[2011/02/02 12:45:15 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CmdLineExt03.dll
[2009/09/03 11:51:44 | 000,780,292 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/09/03 11:32:05 | 000,146,432 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/09/03 11:32:05 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:59:36 | 000,982,196 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 21:59:36 | 000,139,824 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 21:59:36 | 000,097,448 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 21:59:35 | 000,417,344 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[1998/05/06 18:19:58 | 000,210,944 | —- | C] () – C:\Windows\MSVCRT10.DLL

========== LOP Check ==========

[2011/02/02 12:45:24 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\Atari
[2012/01/08 13:19:11 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\BitTorrent
[2012/01/09 00:07:48 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\Dropbox
[2011/02/25 12:49:49 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\EditPlus 3
[2012/01/08 02:45:34 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\FreeFileViewer
[2011/12/14 13:41:31 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\HTC
[2011/04/20 15:52:15 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011/05/25 17:06:40 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\OpenOffice.org
[2011/01/26 15:48:27 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\PCToolsFirewallPlus
[2012/01/07 01:00:41 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\Serif
[2011/02/17 13:32:26 | 000,000,000 | —D | M] – C:\Users\Daughtry\AppData\Roaming\Template
[2012/01/10 12:39:05 | 000,000,408 | —- | M] () – C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
[2011/11/24 01:26:54 | 000,032,620 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 01:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 01:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 01:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/14 01:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/06/04 17:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/06/04 17:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysNative\drivers\iaStor.sys
[2009/06/04 17:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009/06/04 17:43:16 | 000,330,264 | —- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysNative\drivers\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 01:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\SysNative\netlogon.dll
[2009/07/14 01:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 01:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2009/07/14 01:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\SysNative\drivers\nvraid.sys
[2009/07/14 01:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvraid.sys
[2009/07/14 01:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysNative\drivers\nvstor.sys
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 01:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 01:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\SysNative\scecli.dll
[2009/07/14 01:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C31F31E6

< End of report >
OTL Extras logfile created on: 10/01/2012 18:17:50 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Daughtry\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.25 Gb Available Physical Memory | 81.44% Memory free
7.99 Gb Paging File | 7.29 Gb Available in Paging File | 91.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 58.59 Gb Total Space | 12.19 Gb Free Space | 20.81% Space Free | Partition Type: NTFS
Drive D: | 229.63 Gb Total Space | 227.29 Gb Free Space | 98.98% Space Free | Partition Type: NTFS
Drive R: | 9.77 Gb Total Space | 4.32 Gb Free Space | 44.26% Space Free | Partition Type: NTFS

Computer Name: DAUGHTRY-PC | User Name: Daughtry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{10193AAA-D72D-4A1A-B8AD-A9D9221595E7}" = Intel® PROSet/Wireless WiFi Driver
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{EB773820-0871-46A8-9B96-F2B04F8B34F0}" = HP Deskjet All-In-One Driver Software 13.0 Rel. 1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"CCleaner" = CCleaner
"EPSON S21 Series" = EPSON S21 Series Printer Uninstall
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"ProInst" = Intel PROSet Wireless
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04F3038E-4120-44CC-B330-E05F737246A5}" = Roxio Update Manager
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23538B53-1A87-4728-AC4B-869345AA067D}" = Community Smartbar
"{2640314A-2D9A-4F58-B501-DB109CD9DBA2}" = DJ_AIO_ProductContext
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 30
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32DACAC3-6538-405D-915E-8F2D026F199C}" = DJ_AIO_Software_min
"{33311EA4-0ECA-4E7F-83E5-8A92CD760152}" = Serif DrawPlus Starter Edition
"{33cc8e60-d6db-45be-9276-b6698187688a}" = F2100
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{526B2AE8-73DF-4CE0-B140-9968677A7C93}" = HTC Sync
"{56131553-DA50-47FF-AA90-4508F6BFE581}_is1" = Tomb Raider - Legend
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7A1F1E81-A017-43EE-8A24-E88878164C91}" = SeaWorld Adventure Parks Tycoon 3D
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{A0765939-76F5-48D8-82B1-8D0BBFAD0702}" = Serif PhotoPlus Starter Edition
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR
"{AD99B476-6FB7-4985-A3C3-E40595A7E6DE}" = DJ_AIO_Software
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C1920D73-7374-49d9-8C37-58A6E49078A5}" = F2100_Help
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
"Adobe AIR" = Adobe AIR
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Webcam Central" = Dell Webcam Central
"Downloader" = Downloader
"Extensis Intellihance Pro 4.0" = Extensis Intellihance Pro 4.0
"FreeFileViewer_is1" = Free File Viewer 2011
"FYZip" = FYZip 1.00
"HotspotShield" = Hotspot Shield 2.23
"KPT Gel" = KPT Gel
"PC Tools Firewall Plus" = PC Tools Firewall Plus 7.0
"Plugin Commander Light 1.61_is1" = Plugin Commander Light 1.61
"PriceGong" = PriceGong 2.5.0
"Shockwave" = Shockwave
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Trusted Software Assistant_is1" = File Type Assistant
"VDMSound" = VDMSound
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Searchqu Toolbar" = Windows iLivid Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 06/01/2012 21:20:07 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:20:07 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:20:07 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:20:09 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:20:09 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:20:09 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:27:22 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:27:22 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 06/01/2012 21:27:22 | Computer Name = Daughtry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 07/01/2012 10:58:25 | Computer Name = Daughtry-PC | Source = Application Hang | ID = 1002
Description = The program Plug-ins.exe version 0.0.0.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 16b8 Start
Time: 01cccd4cb67c270e Termination Time: 7 Application Path: C:\Users\Daughtry\AppData\Local\Temp\7zO36BA.tmp\Plug-ins.exe

Report
Id: 06e15bb5-3940-11e1-96ad-fa6a30f83f20

[ System Events ]
Error - 21/08/2011 20:23:43 | Computer Name = Daughtry-PC | Source = APPHOSTSVC | ID = 9010
Description =

Error - 22/08/2011 14:28:18 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AcfXAudioService
service to connect.

Error - 22/08/2011 14:28:18 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7000
Description = The AcfXAudioService service failed to start due to the following
error: %%1053

Error - 22/08/2011 14:28:18 | Computer Name = Daughtry-PC | Source = APPHOSTSVC | ID = 9010
Description =

Error - 22/08/2011 19:35:12 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AcfXAudioService
service to connect.

Error - 22/08/2011 19:35:12 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7000
Description = The AcfXAudioService service failed to start due to the following
error: %%1053

Error - 22/08/2011 19:35:13 | Computer Name = Daughtry-PC | Source = APPHOSTSVC | ID = 9010
Description =

Error - 23/08/2011 09:44:20 | Computer Name = Daughtry-PC | Source = APPHOSTSVC | ID = 9010
Description =

Error - 23/08/2011 09:44:19 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the AcfXAudioService
service to connect.

Error - 23/08/2011 09:44:19 | Computer Name = Daughtry-PC | Source = Service Control Manager | ID = 7000
Description = The AcfXAudioService service failed to start due to the following
error: %%1053


< End of report >
exeHelper by Raktor Build 20100414 Run at 18:13:41 on 01/10/12 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

OK, now that I can see what we are dealing with, let’s start getting rid of the bad stuff.

Uninstall the following programs:

PriceGong 2.5.0
Windows iLivid Toolbar

1. From the Start menu, select Control Panel.
2. In Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
3. Select the above programs one at a time and click Uninstall. Alternatively, right-click the program and select Uninstall.
================================================

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.5.0\PriceGongIE.dll (PriceGong)
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    [2012/01/08 02:35:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
    [2012/01/08 02:35:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows iLivid Toolbar
    [2012/01/08 02:27:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
================================================

Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with next post:

OTL fix log
New OTL log
Mbam.txt


Please let me know how your computer is running now.

Satchfan
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}\ not found. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\BrowserConnection.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}\ not found. File C:\Program Files (x86)\PriceGong\2.5.0\PriceGongIE.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully. File pInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found. C:\Program Files (x86)\iLivid\VLC\skins\fonts folder moved successfully. C:\Program Files (x86)\iLivid\VLC\skins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\lib\pkgconfig folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\lib folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include\vlc\plugins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include\vlc folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\plugins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\volume folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\selection folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\selected folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\NSIS folder moved successfully. C:\Program Files (x86)\iLivid\VLC\mozilla folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\sd folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\playlist folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\modules folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\reader folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\fetcher folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\art folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\intf\modules folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\intf folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\requests folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\js folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\images folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\dialogs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\extensions folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_TW\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_TW folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_CN\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_CN folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\wa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\wa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\vi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\vi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\uk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\uk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\th\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\th folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tet\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tet folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ta\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ta folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sv\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sv folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sq\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sq folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\si\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\si folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ru\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ru folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ro\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ro folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\qt4 folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_PT\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_PT folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_BR\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_BR folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ps\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ps folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\oc\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\oc folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ne\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ne folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nb\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nb folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\my\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\my folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ms\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ms folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ml\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ml folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lv\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lv folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lt\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lt folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ko\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ko folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\km\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\km folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\kk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\kk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ka\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ka folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ja\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ja folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\it\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\it folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\is\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\is folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\id\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\id folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hy\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hy folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\he\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\he folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\gl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\gl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ga\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ga folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fur\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fur folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ff\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ff folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\eu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\eu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\et\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\et folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\es\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\es folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\en_GB\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\en_GB folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\el\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\el folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\de\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\de folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\da\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\da folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cs\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\co\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\co folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ckb\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ckb folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cgg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cgg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ca\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ca folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\br\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\br folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\be\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\be folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ast\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ast folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ar\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ar folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\am\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\am folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\af\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\af folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ach\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ach folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale folder moved successfully. C:\Program Files (x86)\iLivid\VLC\languages folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\requests folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\js folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\images folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\dialogs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http folder moved successfully. C:\Program Files (x86)\iLivid\VLC\activex folder moved successfully. C:\Program Files (x86)\iLivid\VLC folder moved successfully. C:\Program Files (x86)\iLivid\imageformats folder moved successfully. C:\Program Files (x86)\iLivid folder moved successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar folder moved successfully. C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr folder moved successfully. C:\Program Files (x86)\Windows iLivid Toolbar folder moved successfully. C:\Program Files (x86)\Free Offers from Freeze.com folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Daughtry ->Temp folder emptied: 52365040 bytes ->Temporary Internet Files folder emptied: 50675456 bytes ->Java cache emptied: 3766865 bytes ->Google Chrome cache emptied: 21898091 bytes ->Flash cache emptied: 57309 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 7545 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67697 bytes RecycleBin emptied: 2063040 bytes Total Files Cleaned = 125.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 01112012_003233 Files\Folders moved on Reboot… C:\Users\Daughtry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI