:Processes Explorer.EXE :OTL IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/ FF - prefs.js…browser.search.defaultenginename: “BearShare Web Search” FF - prefs.js…browser.search.order.1: “BearShare Web Search” FF - prefs.js…keyword.URL: “http://search.bearshare.com/webResults.html?src=ffb&q=” [2009-12-03 10:54:24 | 000,002,476 | ---- | M] () – C:\Users\Pc\AppData\Roaming\Mozilla\FireFox\Profiles\e1nfu0as.default\searchplugins\BearShareWebSearch.xml [2009-12-03 10:54:24 | 000,002,476 | ---- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\BearShareWebSearch.xml O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files (x86)\BearShare Applications\MediaBar\DataMngr\IEBHO.dll File not found O3 - HKLM…\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files (x86)\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll File not found [2010-03-03 17:38:56 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TemppqV728.html [2010-03-03 17:38:56 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempBsh728.html [2010-03-03 17:35:39 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempXY3332.html [2010-03-03 17:35:39 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempBY3332.html [2010-03-01 17:09:19 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempdO4004.html [2010-03-01 17:09:19 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempDL4004.html [2010-02-28 21:30:37 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\Tempqh4092.html [2010-02-28 21:30:37 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempmX4092.html [2010-02-28 15:44:38 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempmV2848.html [2010-02-28 15:44:38 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\Tempfh2848.html [2010-02-27 16:47:31 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\Temphcu856.html [2010-02-27 16:47:31 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempPSY856.html [2010-02-23 19:11:45 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempFa2168.html [2010-02-23 19:11:45 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempOf2168.html [2010-02-20 21:17:54 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempXb3160.html [2010-02-20 21:17:54 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempTy3160.html [2010-02-20 19:40:29 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempNKh180.html [2010-02-20 19:40:29 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempaSs180.html [2010-02-14 15:58:32 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\Tempkc1208.html [2010-02-14 15:58:32 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\Tempig1208.html [2010-02-11 16:36:35 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempRl3588.html [2010-02-11 16:36:35 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempZR3588.html [2010-02-08 15:04:34 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\Tempzze844.html [2010-02-08 15:04:34 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempPiI844.html [2010-02-03 21:03:46 | 000,002,432 | ---- | M] () – C:\Users\Pc\AppData\Local\TempZZ3272.html [2010-02-03 21:03:46 | 000,002,089 | ---- | M] () – C:\Users\Pc\AppData\Local\TempQT3272.html [2010-01-24 15:08:00 | 000,002,432 | ---- | C] () – C:\Users\Pc\AppData\Local\TempkB4220.html [2010-01-24 15:08:00 | 000,002,089 | ---- | C] () – C:\Users\Pc\AppData\Local\TempMK4220.html :Commands [emptytemp] [start explorer]