1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Help Please Bob12A

Discussion in 'Malware Removal Help' started by bob12a, Dec 15, 2011.

  1. KenB

    KenB Registered Members

    Joined:
    Oct 21, 2010
    Messages:
    1,223
    Location:
    Wirral UK
    Operating System:
    Windows Vista Home Premium
    Let us know how it goes :)

    Happy New Year Bob.
     
  2. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Hi Ken
    Reinstalled chrome no different effect

    Had another thought I do have malwarebytes pro installed
    Some in there forum has asked the same question


    it is at the following link I WILL UNDERSTAND IF YOU DONT WANT TO USE THIS LINK.
    I am not savy enough to understand what the answer is


    http://forums.malwarebytes.org/index.php?showtopic=88900&st=0&p=449892&hl="error%20138"&fromsearch=1&#entry449892
     
  3. KenB

    KenB Registered Members

    Joined:
    Oct 21, 2010
    Messages:
    1,223
    Location:
    Wirral UK
    Operating System:
    Windows Vista Home Premium
    Hi Bob,

    I don't have MBAM Pro - perhaps Starbuck may be able to help out here ?

    Is this the suggestion you are having problems understanding?
     
  4. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Yes Ken Thanks.
    Will wait until maybe SB sees this.
    What IP address are they refering to and how do I find it.
    Kindest again
    Bob
     
  5. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    Unfortunately i don't use the Pro version of MBAM either.
    From what i understand you have an intermitant problem with Chrome not accessing the internet?
    The link to malwarebytes refers to a problem with individual sites.
    The explanation is how to allow these sites.
    If you are not getting on to the Internet in the first place, that explanation won't apply.

    You say that you are using Microsoft Security Essentials...... but your sig says you use AVG Pro!
    Has AVG been completely removed from the system?
    Your sig also says you are using ZA Pro ...... are you still running this?
    If you are.... have you turned off the Windows Firewall?
     
  6. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    SB will reply after I have checked out your questions AND UPDATED MY SIG
    Bob
     
  7. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Thanks SB replies in CAPS above

    Bob
     
  8. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    As you're not sure if AVG has been completely removed:

    To remove AVG go to:
    http://www.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

    download to your desktop.
    then double click to start the uninstaller.

    This should remove all traces for you.
    Then maybe we should have a look and see if there's anything on the system that may be causing this:

    • Download OTL to your desktop.
      right click on the link and select 'Save Link/Target As'.

      if you have problems, try this download link:
      OTL
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    .
    .

    Now copy the lines in bold below.

    netsvcs
    msconfig
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.exe /lockedfiles
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\*
    %USERPROFILE%\..|smtmp;true;true;true /FP
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    CREATERESTOREPOINT


    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
      .
    • Click the Run Scan button.

      [​IMG]
    • Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.


    Thanks
     
    Last edited by a moderator: Feb 4, 2014
  9. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Thanks SB received and understood will be a few hours before I can carry out your instructions
    Bob
     
  10. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Hi Friend
    hope this is what you ask for
    Bob

    OTL logfile created on: 02/01/2012 15:09:00 - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\BF2010\Downloads
    Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    3.25 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 64.53% Memory free
    6.50 Gb Paging File | 5.25 Gb Available in Paging File | 80.83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 910.41 Gb Total Space | 704.21 Gb Free Space | 77.35% Space Free | Partition Type: NTFS
    Drive D: | 20.00 Gb Total Space | 10.62 Gb Free Space | 53.09% Space Free | Partition Type: NTFS

    Computer Name: BF2010-PC | User Name: BF2010 | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - C:\Users\BF2010\Downloads\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
    PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
    PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
    PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
    PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
    PRC - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
    PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
    PRC - C:\Program Files\Secunia\PSI\psia.exe (Secunia)
    PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
    PRC - C:\Windows\explorer.exe (Microsoft Corporation)
    PRC - C:\Windows\System32\atieclxx.exe (AMD)
    PRC - C:\Windows\System32\atiesrxx.exe (AMD)
    PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
    PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
    PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
    PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
    PRC - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)


    ========== Modules (No Company Name) ==========

    MOD - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\ppgooglenaclpluginchrome.dll ()
    MOD - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll ()
    MOD - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\avutil-51.dll ()
    MOD - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\avformat-53.dll ()
    MOD - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\avcodec-53.dll ()
    MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
    MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
    MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()


    ========== Win32 Services (SafeList) ==========

    SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
    SRV - (Akamai) -- c:\program files\common files\akamai etsession_win_b427739.dll ()
    SRV - (RapportMgmtService) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
    SRV - (TuneUp.Defrag) -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
    SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
    SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software)
    SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
    SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
    SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
    SRV - (Secunia PSI Agent) -- C:\Program Files\Secunia\PSI\PSIA.exe (Secunia)
    SRV - (Secunia Update Agent) -- C:\Program Files\Secunia\PSI\sua.exe (Secunia)
    SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
    SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
    SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
    SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    SRV - (PSI_SVC_2) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
    SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
    SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (MpKslc08566ed) -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8FB7F055-ED8B-4AC6-96FA-D696DF45E3C3}\MpKslc08566ed.sys (Microsoft Corporation)
    DRV - (RapportCerberus_34302) -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys ()
    DRV - (RapportPG) -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
    DRV - (RapportEI) -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
    DRV - (RapportKELL) -- C:\Windows\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
    DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
    DRV - (RapportIaso) -- c:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys (Trusteer Ltd.)
    DRV - (iBtFltCoex) -- C:\Windows\System32\drivers\iBtFltCoex.sys (Intel Corporation)
    DRV - (btmhsf) -- C:\Windows\System32\drivers\btmhsf.sys (Intel Corporation)
    DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
    DRV - (MpNWMon) -- C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
    DRV - (dc3d) -- C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
    DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
    DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
    DRV - (RTL8192su) -- C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
    DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdW73.sys (ATI Technologies, Inc.)
    DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
    DRV - (btusbflt) -- C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
    DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
    DRV - (TuneUpUtilitiesDrv) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
    DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
    DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
    DRV - (amdide) -- C:\Windows\system32\DRIVERS\amdide.sys (Advanced Micro Devices Inc.)
    DRV - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
    DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
    DRV - (USBPNPA) -- C:\Windows\System32\drivers\CM108.sys (C-Media Inc)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========


    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

    ========== FireFox ==========


    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@google.com pPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\BF2010\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\BF2010\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/10/30 16:36:46 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/12/16 15:10:41 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/26 20:49:17 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/17 12:49:12 | 000,000,000 | ---D | M]

    [2011/12/26 15:05:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BF2010\AppData\Roaming\Mozilla\Extensions
    [2010/07/24 09:37:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BF2010\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com
    [2012/01/01 16:17:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BF2010\AppData\Roaming\Mozilla\Firefox\Profiles\cd9e1ckw.default\extensions
    [2011/12/18 09:14:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BF2010\AppData\Roaming\Mozilla\Firefox\Profiles\n0cs74ko.default\extensions
    [2011/09/21 05:43:07 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\BF2010\AppData\Roaming\Mozilla\Firefox\Profiles\n0cs74ko.default\extensions\ffxtlbr@Facemoods.com
    [2011/12/22 18:38:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2011/12/19 16:03:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    [2011/12/17 05:09:01 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2009/08/03 14:07:42 | 000,373,104 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
    [2011/12/22 18:38:48 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml

    ========== Chrome ==========

    CHR - default_search_provider: Search Results (Enabled)
    CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
    CHR - default_search_provider: suggest_url =
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\BF2010\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
    CHR - plugin: Skype Toolbars (Enabled) = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_0\npSkypeChromePlugin.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
    CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
    CHR - plugin: Office Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll
    CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
    CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
    CHR - plugin: Java(TM) Platform SE 7 U2 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
    CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
    CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
    CHR - plugin: Default Plug-in (Enabled) = default_plugin
    CHR - Extension: YouTube = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
    CHR - Extension: Google Search = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
    CHR - Extension: Facemoods = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.4.1_1\
    CHR - Extension: Skype Click to Call = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.8.0.8855_1\
    CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
    CHR - Extension: Gmail = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

    Hosts file not found
    O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
    O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
    O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
    O4 - Startup: C:\Users\BF2010\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk = C:\Program Files\FireTrust\MailWasher\MailWasherPro.exe (Firetrust)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
    O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
    O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
    O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
    O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
    O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
    O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
    O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.0)
    O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB30CD2B-150C-4391-9125-F421E94225E0}: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GO36F4~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found

    MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk - - File not found
    MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MailWasherPro.lnk - C:\Program Files\FireTrust\MailWasher\MailWasherPro.exe - (Firetrust)
    MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe - (Secunia)
    MsConfig - StartUpFolder: C:^Users^BF2010^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk - C:\Users\BF2010\AppData\Roaming\Dropbox\bin\Dropbox.exe - (Dropbox, Inc.)
    MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    MsConfig - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    MsConfig - StartUpReg: AdobeCS5ServiceManager - hkey= - key= - C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
    MsConfig - StartUpReg: Akamai NetSession Interface - hkey= - key= - C:\Users\BF2010\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
    MsConfig - StartUpReg: Application Restart #1 - hkey= - key= - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
    MsConfig - StartUpReg: Application Restart #2 - hkey= - key= - C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
    MsConfig - StartUpReg: CanonSolutionMenu - hkey= - key= - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
    MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    MsConfig - StartUpReg: facemoods - hkey= - key= - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com)
    MsConfig - StartUpReg: FlashGet 3 - hkey= - key= - C:\Program Files\FlashGet Network\FlashGet 3\Flashget3.exe (Trend Media Corporation Limited)
    MsConfig - StartUpReg: Gadwin PrintScreen - hkey= - key= - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
    MsConfig - StartUpReg: Google Update - hkey= - key= - C:\Users\BF2010\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
    MsConfig - StartUpReg: GrooveMonitor - hkey= - key= - File not found
    MsConfig - StartUpReg: iTunesHelper - hkey= - key= - File not found
    MsConfig - StartUpReg: LDM - hkey= - key= - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe ()
    MsConfig - StartUpReg: NBAgent - hkey= - key= - File not found
    MsConfig - StartUpReg: Nikon Message Center 2 - hkey= - key= - C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
    MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
    MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
    MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    MsConfig - StartUpReg: SwitchBoard - hkey= - key= - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    MsConfig - StartUpReg: TkBellExe - hkey= - key= - File not found
    MsConfig - StartUpReg: {0228e555-4f9c-4e35-a3ec-b109a192b4c2} - hkey= - key= - File not found
    MsConfig - State: "startup" - 2

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/12/31 14:23:23 | 000,000,000 | ---D | C] -- C:\Users\BF2010\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2011/12/27 18:05:15 | 000,000,000 | ---D | C] -- C:\Users\BF2010\AppData\Roaming\PerformerSoft
    [2011/12/27 18:05:12 | 000,017,464 | ---- | C] (PerformerSoft LLC) -- C:\Windows\System32\roboot.exe
    [2011/12/22 18:39:46 | 000,000,000 | ---D | C] -- C:\Users\BF2010\AppData\Local\Ilivid Player
    [2011/12/22 18:39:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\~0
    [2011/12/22 18:39:17 | 000,000,000 | ---D | C] -- C:\Program Files\iLivid
    [2011/12/22 18:38:49 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
    [2011/12/22 18:38:48 | 000,000,000 | ---D | C] -- C:\Program Files\Windows iLivid Toolbar
    [2011/12/22 15:27:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ViewNX 2
    [2011/12/19 16:02:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    [2011/12/19 16:02:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
    [2011/12/19 16:02:35 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
    [2011/12/19 07:47:19 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2011/12/19 07:47:18 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/12/19 07:47:17 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/12/19 07:47:16 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/12/19 07:47:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/12/19 07:47:10 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/12/18 15:18:34 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/12/18 15:18:33 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/12/18 15:18:33 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/12/18 15:18:33 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/12/18 15:18:33 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/12/18 15:18:33 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/12/18 15:18:33 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/12/18 15:18:32 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/12/18 15:18:32 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/12/18 15:18:32 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/12/18 15:18:32 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/12/18 15:18:32 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/12/18 15:18:32 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/12/18 15:18:32 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/12/18 15:18:32 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/12/18 15:18:32 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/12/18 15:18:32 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/12/18 15:18:32 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/12/18 15:18:32 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/12/18 15:18:32 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/12/18 15:18:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/12/18 15:18:32 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/12/18 15:18:32 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/12/18 15:18:31 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/12/18 15:18:31 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/12/18 15:18:31 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/12/18 15:18:31 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/12/18 15:18:31 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/12/18 15:18:31 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/12/18 15:18:31 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/12/18 15:18:31 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/12/18 12:26:39 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
    [2011/12/18 12:26:38 | 000,000,000 | ---D | C] -- C:\Program Files\Free Notes & Office Ink
    [2011/12/18 12:23:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Tablet
    [2011/12/17 12:50:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2011/12/17 12:49:12 | 000,637,848 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
    [2011/12/17 12:49:12 | 000,223,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
    [2011/12/17 12:49:12 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
    [2011/12/17 12:49:12 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
    [2011/12/16 15:11:35 | 000,000,000 | ---D | C] -- C:\Users\BF2010\AppData\Local\DDMSettings
    [2011/12/16 09:38:07 | 002,340,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
    [2011/12/16 09:37:22 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
    [2011/12/16 09:36:38 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
    [2011/12/16 09:33:58 | 003,957,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
    [2011/12/16 09:33:58 | 003,901,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
    [2011/12/14 12:23:32 | 000,056,208 | ---- | C] (Trusteer Ltd.) -- C:\Windows\System32\drivers\RapportKELL.sys
    [2011/12/13 22:34:27 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
    [2011/12/12 07:21:25 | 000,000,000 | ---D | C] -- C:\ProgramData\ErrorEND
    [2011/12/10 09:40:24 | 000,030,016 | ---- | C] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll
    [2011/12/10 09:40:24 | 000,021,312 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
    [2011/12/10 08:24:04 | 000,481,584 | ---- | C] (Microsoft Corporation) -- C:\Users\BF2010\IE9-Windows7-x86-enu.exe
    [2011/12/09 18:15:44 | 000,417,440 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
    [2011/12/09 11:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firetrust
    [2011/12/05 12:36:06 | 000,000,000 | ---D | C] -- C:\Users\BF2010\AppData\Roaming\Avant Downloader
    [2011/12/05 10:36:12 | 000,000,000 | ---D | C] -- C:\Windows\en
    [2011/12/05 10:18:48 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
    [2011/12/05 10:18:48 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
    [2011/12/04 08:27:59 | 000,000,000 | R--D | C] -- C:\Users\BF2010\Desktop\PAUL TEACHING BOB
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/01/02 14:35:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/01/02 14:27:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2785784116-2001642337-1380054423-1000UA.job
    [2012/01/02 14:27:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2785784116-2001642337-1380054423-1000Core.job
    [2012/01/02 14:24:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/01/02 12:56:52 | 000,015,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/01/02 12:56:52 | 000,015,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/01/02 12:49:43 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/01/02 12:49:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/01/02 12:39:43 | 000,000,147 | ---- | M] () -- C:\Users\BF2010\Desktop\Sign Out.url
    [2012/01/02 12:32:01 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
    [2012/01/02 11:24:25 | 000,008,248 | ---- | M] () -- C:\Users\BF2010\Desktop\anns icon.jpg
    [2012/01/02 06:59:30 | 000,677,316 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2012/01/02 06:59:30 | 000,132,016 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2012/01/01 16:17:35 | 000,002,065 | ---- | M] () -- C:\Users\BF2010\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 4.0 Beta 9.lnk
    [2012/01/01 16:01:28 | 000,120,278 | ---- | M] () -- C:\Windows\Gas _elec_water 12a 04 2012.ods
    [2011/12/31 14:23:25 | 000,002,326 | ---- | M] () -- C:\Users\BF2010\Desktop\Google Chrome.lnk
    [2011/12/31 08:43:17 | 000,001,059 | ---- | M] () -- C:\Users\BF2010\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
    [2011/12/31 08:43:17 | 000,001,035 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2011/12/30 14:40:59 | 000,002,503 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2011/12/27 08:29:22 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
    [2011/12/26 11:00:06 | 000,090,113 | ---- | M] () -- C:\Users\BF2010\Desktop\breadwater2.jpg
    [2011/12/24 16:29:39 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLet.DAT
    [2011/12/24 07:41:08 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLev.DAT
    [2011/12/23 14:56:54 | 000,096,726 | ---- | M] () -- C:\Users\BF2010\Desktop\Capture 12.JPG
    [2011/12/22 17:31:31 | 000,000,984 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2011/12/22 15:27:54 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Strings
    [2011/12/22 15:27:54 | 000,000,268 | RH-- | M] () -- C:\Users\BF2010\AppData\Roaming\StatusSheet
    [2011/12/22 15:27:54 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLes.DAT
    [2011/12/22 15:27:54 | 000,000,012 | RH-- | M] () -- C:\ProgramData\Textures
    [2011/12/22 15:27:08 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\ViewNX 2.lnk
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Super Strings
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | M] () -- C:\ProgramData\String Ensemble
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | M] () -- C:\Users\BF2010\AppData\Roaming\Stingers
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | M] () -- C:\Users\BF2010\AppData\Roaming\Static Library
    [2011/12/22 15:26:41 | 000,000,012 | RH-- | M] () -- C:\ProgramData\Track Settings
    [2011/12/22 15:26:41 | 000,000,012 | RH-- | M] () -- C:\ProgramData\Techno Kit
    [2011/12/22 15:25:49 | 000,000,000 | ---- | M] () -- C:\ProgramData\StatusSheet
    [2011/12/22 15:25:46 | 000,000,000 | ---- | M] () -- C:\ProgramData\StartupItems
    [2011/12/22 15:25:21 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ATL71.DLL
    [2011/12/22 10:48:54 | 000,003,128 | ---- | M] () -- C:\Users\BF2010\Documents\cc_20111222_104840.reg
    [2011/12/21 16:32:14 | 000,071,865 | ---- | M] () -- C:\Users\BF2010\Desktop\Capture11.PNG
    [2011/12/21 16:31:05 | 000,001,456 | ---- | M] () -- C:\Users\BF2010\AppData\Local\Adobe Save for Web 12.0 Prefs
    [2011/12/21 15:24:10 | 000,417,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
    [2011/12/21 15:24:10 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
    [2011/12/20 17:17:38 | 000,011,214 | ---- | M] () -- C:\Users\BF2010\Documents\brian amazon order.odt
    [2011/12/20 15:23:48 | 000,000,945 | ---- | M] () -- C:\Users\BF2010\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
    [2011/12/20 15:23:48 | 000,000,921 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
    [2011/12/18 15:18:34 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/12/18 15:18:33 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/12/18 15:18:33 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/12/18 15:18:33 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/12/18 15:18:33 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/12/18 15:18:33 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/12/18 15:18:33 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/12/18 15:18:32 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/12/18 15:18:32 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/12/18 15:18:32 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/12/18 15:18:32 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/12/18 15:18:32 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/12/18 15:18:32 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/12/18 15:18:32 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/12/18 15:18:32 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/12/18 15:18:32 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/12/18 15:18:32 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/12/18 15:18:32 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/12/18 15:18:32 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/12/18 15:18:32 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2011/12/18 15:18:32 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/12/18 15:18:32 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/12/18 15:18:32 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/12/18 15:18:31 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/12/18 15:18:31 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/12/18 15:18:31 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/12/18 15:18:31 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/12/18 15:18:31 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/12/18 15:18:31 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/12/18 15:18:31 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/12/18 15:18:31 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/12/17 16:14:35 | 000,019,306 | ---- | M] () -- C:\Users\BF2010\Desktop\bobs BP 03.ods
    [2011/12/17 12:48:59 | 000,637,848 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
    [2011/12/17 12:48:59 | 000,567,184 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
    [2011/12/17 12:48:59 | 000,223,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
    [2011/12/17 12:48:59 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
    [2011/12/17 12:48:59 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
    [2011/12/16 14:17:58 | 003,868,144 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/12/16 10:54:26 | 000,606,536 | ---- | M] (Google Inc.) -- C:\Users\BF2010\ChromeSetup.exe
    [2011/12/16 10:51:10 | 000,001,966 | ---- | M] () -- C:\Users\BF2010\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2011/12/16 10:50:01 | 014,761,224 | ---- | M] (Mozilla) -- C:\Users\BF2010\Firefox Setup 8.0.1.exe
    [2011/12/14 12:23:32 | 000,056,208 | ---- | M] (Trusteer Ltd.) -- C:\Windows\System32\drivers\RapportKELL.sys
    [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [2011/12/10 09:40:09 | 000,002,091 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
    [2011/12/10 09:40:09 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities.lnk
    [2011/12/10 08:28:40 | 000,481,584 | ---- | M] (Microsoft Corporation) -- C:\Users\BF2010\IE9-Windows7-x86-enu.exe
    [2011/12/09 11:56:42 | 000,001,074 | ---- | M] () -- C:\Users\BF2010\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk
    [2011/12/09 11:56:42 | 000,001,036 | ---- | M] () -- C:\Users\Public\Desktop\MailWasherPro.lnk
    [2011/12/05 15:38:22 | 000,230,240 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
    [2011/12/03 16:31:15 | 000,000,326 | -H-- | M] () -- C:\Users\BF2010\.picasa.ini
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/02 12:39:43 | 000,000,147 | ---- | C] () -- C:\Users\BF2010\Desktop\Sign Out.url
    [2012/01/02 10:28:04 | 000,008,248 | ---- | C] () -- C:\Users\BF2010\Desktop\anns icon.jpg
    [2012/01/01 15:49:05 | 000,120,278 | ---- | C] () -- C:\Windows\Gas _elec_water 12a 04 2012.ods
    [2011/12/31 14:23:25 | 000,002,326 | ---- | C] () -- C:\Users\BF2010\Desktop\Google Chrome.lnk
    [2011/12/31 14:22:34 | 000,000,912 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2785784116-2001642337-1380054423-1000UA.job
    [2011/12/31 14:22:33 | 000,000,860 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2785784116-2001642337-1380054423-1000Core.job
    [2011/12/27 11:22:39 | 000,001,059 | ---- | C] () -- C:\Users\BF2010\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
    [2011/12/27 11:22:38 | 000,001,035 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2011/12/25 17:55:27 | 000,090,113 | ---- | C] () -- C:\Users\BF2010\Desktop\breadwater2.jpg
    [2011/12/23 14:56:54 | 000,096,726 | ---- | C] () -- C:\Users\BF2010\Desktop\Capture 12.JPG
    [2011/12/22 15:27:54 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Strings
    [2011/12/22 15:27:54 | 000,000,268 | RH-- | C] () -- C:\Users\BF2010\AppData\Roaming\StatusSheet
    [2011/12/22 15:27:54 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Textures
    [2011/12/22 15:27:08 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\ViewNX 2.lnk
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Super Strings
    [2011/12/22 15:26:41 | 000,000,268 | RH-- | C] () -- C:\ProgramData\String Ensemble
    [2011/12/22 15:26:41 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Track Settings
    [2011/12/22 15:26:41 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Techno Kit
    [2011/12/22 15:25:49 | 000,000,000 | ---- | C] () -- C:\ProgramData\StatusSheet
    [2011/12/22 15:25:46 | 000,000,000 | ---- | C] () -- C:\ProgramData\StartupItems
    [2011/12/22 10:48:47 | 000,003,128 | ---- | C] () -- C:\Users\BF2010\Documents\cc_20111222_104840.reg
    [2011/12/20 17:17:35 | 000,011,214 | ---- | C] () -- C:\Users\BF2010\Documents\brian amazon order.odt
    [2011/12/20 15:23:48 | 000,000,921 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
    [2011/12/19 16:02:38 | 000,002,503 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
    [2011/12/18 15:18:32 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2011/12/18 12:24:15 | 000,000,969 | ---- | C] () -- C:\Windows\System32\Corel Draw Essential X5.ini
    [2011/12/18 12:24:15 | 000,000,963 | ---- | C] () -- C:\Windows\System32\Corel Draw Essential 4.ini
    [2011/12/18 12:23:48 | 000,010,708 | ---- | C] () -- C:\Windows\System32\aiptbl.ini
    [2011/12/15 15:44:19 | 000,071,865 | ---- | C] () -- C:\Users\BF2010\Desktop\Capture11.PNG
    [2011/12/10 09:40:09 | 000,002,091 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
    [2011/12/10 09:40:09 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities.lnk
    [2011/12/09 18:15:45 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2011/12/09 11:56:42 | 000,001,036 | ---- | C] () -- C:\Users\Public\Desktop\MailWasherPro.lnk
    [2011/12/05 10:30:41 | 000,002,396 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
    [2011/08/13 15:24:01 | 000,000,000 | ---- | C] () -- C:\Users\BF2010\AppData\Local\{CB311B15-645B-467F-AB72-A373C4B2F9EB}
    [2011/07/27 09:04:43 | 000,000,000 | ---- | C] () -- C:\Windows\ViewNX2.INI
    [2011/07/27 08:54:42 | 000,000,268 | RH-- | C] () -- C:\Users\BF2010\AppData\Roaming\Stingers
    [2011/07/27 08:54:42 | 000,000,268 | RH-- | C] () -- C:\Users\BF2010\AppData\Roaming\Static Library
    [2011/07/27 08:54:42 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLev.DAT
    [2011/07/27 08:54:42 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLes.DAT
    [2011/07/27 08:54:41 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLet.DAT
    [2011/05/29 07:46:04 | 000,160,693 | ---- | C] () -- C:\Windows\Sqirlz Water Reflections Uninstaller.exe
    [2011/04/17 07:09:43 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
    [2011/04/17 07:09:43 | 000,000,088 | RHS- | C] () -- C:\ProgramData\DE100F8271.sys
    [2011/04/08 08:38:44 | 000,000,047 | ---- | C] () -- C:\Windows\winhlp32.ini
    [2011/04/08 08:38:44 | 000,000,047 | ---- | C] () -- C:\Windows\winhelp.ini
    [2011/04/08 08:37:28 | 000,017,552 | ---- | C] () -- C:\Windows\System32\TTYTWIN.DRV
    [2011/04/08 08:36:43 | 000,022,480 | ---- | C] () -- C:\Windows\System32\PFMAPI16.DLL
    [2011/04/08 08:36:43 | 000,020,992 | ---- | C] () -- C:\Windows\System32\PFMAPI32.DLL
    [2011/01/26 22:12:00 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
    [2010/12/21 02:27:22 | 000,003,113 | ---- | C] () -- C:\Windows\System32\atipblag.dat
    [2010/12/17 16:00:46 | 000,227,587 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
    [2010/11/08 11:35:43 | 000,053,812 | ---- | C] () -- C:\Windows\uninst-vj.exe
    [2010/11/08 09:56:53 | 000,000,090 | ---- | C] () -- C:\Windows\System32\ftm31.dat
    [2010/11/02 16:32:44 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2010/10/30 14:27:25 | 000,007,648 | ---- | C] () -- C:\Users\BF2010\AppData\Local\resmon.resmoncfg
    [2010/10/22 14:45:42 | 000,000,132 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\Adobe PNG Format CS5 Prefs
    [2010/10/09 08:39:05 | 000,000,132 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\Adobe BMP Format CS5 Prefs
    [2010/09/14 19:55:58 | 000,230,240 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
    [2010/09/13 11:54:49 | 000,001,456 | ---- | C] () -- C:\Users\BF2010\AppData\Local\Adobe Save for Web 12.0 Prefs
    [2010/09/02 08:37:07 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
    [2010/08/12 11:50:14 | 000,038,429 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\Comma Separated Values (DOS).ADR
    [2010/07/10 08:51:59 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
    [2010/07/10 08:49:34 | 000,006,211 | ---- | C] () -- C:\Windows\mgxoschk.ini
    [2010/06/30 14:28:50 | 000,038,131 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\mdbu.bin
    [2010/06/25 05:54:54 | 000,000,195 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\ltbpr.dat
    [2010/06/01 14:31:10 | 000,000,000 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\downloads.m3u
    [2010/06/01 12:42:47 | 000,149,504 | ---- | C] () -- C:\Windows\UNWISE.EXE
    [2010/05/19 05:45:28 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
    [2010/05/14 11:23:29 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010/04/09 17:48:57 | 000,007,772 | ---- | C] () -- C:\Windows\System32\secustat.dat
    [2010/04/01 14:55:16 | 000,000,032 | ---- | C] () -- C:\Windows\CD_START.INI
    [2010/03/31 15:42:06 | 000,000,141 | ---- | C] () -- C:\Users\BF2010\AppData\Roaming\default.rss
    [2010/03/27 09:37:32 | 000,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
    [2010/03/26 17:52:37 | 000,025,088 | ---- | C] () -- C:\Users\BF2010\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/03/26 11:35:41 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
    [2010/03/26 07:15:56 | 000,081,920 | R--- | C] () -- C:\Windows\bwUnin-6.1.4.61-8876480L.exe
    [2010/02/16 14:19:22 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2010/02/16 14:01:33 | 000,000,021 | ---- | C] () -- C:\Windows\System32\drivers\VERSION.DAT
    [2009/12/03 09:27:30 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.DLL
    [2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
    [2009/07/14 04:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 04:33:53 | 003,868,144 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2009/07/14 02:05:48 | 000,677,316 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2009/07/14 02:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2009/07/14 02:05:48 | 000,132,016 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2009/07/14 02:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2009/07/14 02:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2009/07/14 02:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2009/07/13 23:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/13 23:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [2009/06/10 21:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

    ========== LOP Check ==========

    [2010/08/20 16:42:26 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Affixa
    [2011/02/09 10:11:49 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Amazon
    [2010/08/24 07:56:59 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\AnvSoft
    [2010/07/13 14:35:48 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\AquaSoft
    [2011/04/04 06:25:42 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Auslogics
    [2011/12/05 12:36:06 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Avant Downloader
    [2011/07/17 08:19:15 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
    [2011/07/09 12:43:48 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\BITS
    [2011/07/12 16:26:09 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\calibre
    [2010/04/02 15:12:03 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Canon
    [2010/09/14 19:53:52 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2010/09/15 08:09:20 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\com.adobe.DC3Module.AdobeADC
    [2011/12/20 06:47:30 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Dropbox
    [2011/01/02 07:56:37 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\FileZilla
    [2011/01/07 15:28:26 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Firetrust
    [2010/04/10 08:08:50 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\FlashGet
    [2010/08/11 09:26:01 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\FlashGetBHO
    [2010/07/24 09:37:09 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Flickr
    [2011/05/29 07:43:31 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\GetRightToGo
    [2011/05/25 05:48:05 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\GoodSync
    [2011/05/24 13:35:10 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\GrabPro
    [2011/05/25 08:16:56 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\ieSpell
    [2011/12/26 20:49:35 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\IrfanView
    [2011/08/25 07:37:27 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\JAM Software
    [2011/11/22 18:14:21 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Kovalev'S.oftware
    [2010/07/12 16:43:24 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\MAGIX
    [2011/01/16 13:21:48 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\MailWasherPro
    [2010/08/20 16:44:52 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Mapi2Xml
    [2010/12/12 15:30:57 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Mobipocket
    [2010/03/30 10:25:18 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\NewSoft
    [2010/05/28 17:58:08 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\NewspaperDirect
    [2011/07/27 11:23:58 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Nikon
    [2010/07/20 06:18:17 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Oloneo
    [2010/09/19 11:33:33 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\OOo-dev
    [2010/03/26 16:53:08 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\OpenOffice.org
    [2010/08/14 07:55:37 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\PDF Software
    [2011/12/28 07:03:39 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\PerformerSoft
    [2010/07/12 14:46:41 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\PhotoScape
    [2010/10/07 10:39:28 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
    [2011/01/06 13:05:07 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Stardock
    [2010/06/16 06:07:42 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\SystemRequirementsLab
    [2010/05/21 08:17:36 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Trusteer
    [2010/12/15 08:26:42 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\TuneUp Software
    [2011/01/07 16:36:05 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\Windows Live Writer
    [2010/04/01 06:31:10 | 000,000,000 | ---D | M] -- C:\Users\BF2010\AppData\Roaming\WordWeb
    [2011/12/08 06:50:33 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2011/11/21 14:32:57 | 000,000,406 | ---- | M] () -- C:\CD Drive - Shortcut.lnk
    [2009/06/10 21:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2010/02/17 16:11:04 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2010/02/17 16:11:04 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2012/01/02 12:49:29 | 3487,883,264 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
    [2009/07/14 01:15:05 | 000,071,168 | ---- | M] (CANON INC.) -- C:\Windows\system32\Spool\prtprocs\w32x86\CNBPP4.DLL
    [2006/10/26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\w32x86\mdippr.dll
    [2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
    [2009/07/14 01:16:19 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\w32x86\winprint.dll

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\system32\drivers\*.sys /lockedfiles >

    < %systemroot%\system32\*.exe /lockedfiles >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\* >
    [2009/07/14 04:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %USERPROFILE%\..|smtmp;true;true;true /FP >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < hklm\software\clients\startmenuinternet|command /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --show-icons [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --hide-icons [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/12/18 15:18:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/12/18 15:18:34 | 000,748,336 | ---- | M] (Microsoft Corporation)

    < hklm\software\clients\startmenuinternet|command /64 /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/12/17 05:09:02 | 000,715,176 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/12/17 05:08:59 | 000,924,632 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --show-icons [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --hide-icons [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Users\BF2010\AppData\Local\Google\Chrome\Application\chrome.exe" [2011/12/07 11:16:29 | 001,047,096 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/12/18 15:18:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/12/18 15:18:34 | 000,748,336 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2011/12/18 15:18:34 | 000,748,336 | ---- | M] (Microsoft Corporation)

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 143 bytes -> C:\Users\BF2010\AppData\Roaming\default.rss:OECustomProperty
    @Alternate Data Stream - 103 bytes -> C:\ProgramData\Temp:DFC5A2B2

    < End of report >
     

    Attached Files:

  11. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    I'll move this thread to the malware removal forum for the time being.

    You do have some questionable items in your report.
    Some of these actually come bundled with legit software.... but they're not something you really want.
    One has even added an extention to your Chrome Browser.... which may or may not have a bearing on your problem.
    Plus there's a site in your trusted zone.... this site is marked as bad on WOT and the McAfee site, so we'll remove that.

    Step 1
    Double click on OTL to run it.
    Copy the lines in bold below. (make sure that :Otl is on the first line )

    :Otl
    CHR - Extension: Facemoods = C:\Users\BF2010\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.4.1_1\
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com)
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    O15 - HKCU\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    MsConfig - StartUpReg: facemoods - hkey= - key= - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com)

    :Files
    C:\Program Files\Windows iLivid Toolbar
    C:\Program Files\facemoods.com
    ipconfig /flushdns /c

    :commands
    [emptytemp]
    [purity]
    [RESETHOSTS]


    • Return to OTL,
    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
    • Click the red Run Fix button.

      [​IMG]
    • OTL will reboot your system once the fix has completed.
    • After the reboot, you may need to double click OTL to launch the program and retrieve the log.

    Copy and paste the contents of the OTL log that comes up after the fix in your next reply.

    if you lose the report, there will be a copy here:
    C:\_OTL\MovedFiles


    Step 2
    I'd like you to do an ESET OnlineScan

    You may find it beneficial to close your resident AV program before running the scan.
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
    • Click the [​IMG] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on [​IMG] to download the ESET Smart Installer.
        Save it to your desktop.
      • Double click on the [​IMG] icon on your desktop.
    • Check [​IMG]
    • Click the [​IMG] button.
    • Accept any security warnings from your browser.
    • Check [​IMG]
    • Click the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [​IMG]
    • Click [​IMG], and save the file to your desktop using a unique name, such as ESETScan.
      Include the contents of this report in your next reply.
    • Click the [​IMG] button.
    • Click [​IMG]
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt


    Note:
    It's been found that on some systems the Eset's Online Scan fails during the database download ( around 20% )
    To prevent this happening:
    When the Computer scan settings display shows, click the Advanced option, the place a check next to the following (if it is not already checked):

    Enable Anti-Stealth technology

    [​IMG]



    In your next reply, please submit:
    Otl fix report
    Eset scan report


    Thanks.
     
    Last edited by a moderator: Feb 4, 2014
  12. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    All of you are so kind for the work you are putting in to help me.
     

    Attached Files:

  13. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    2nd attempt to add log and text file
     

    Attached Files:

  14. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
  15. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    Just for your information:
    This error in the OTL fix report...
    Happened because you copied too much text when adding it to the fix area.
    Nothing to worry about at all.

    OTL and Eset have removed quite a bit, how's the system running now?
     
  16. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    What can I say SB but a big thank you for all the time you and other members have spent helping me with this problem.

    As for the answer to how the system is running I can only hope the ERROR 138 has been corrected in what you led me through
    will keep you informed
    A BIG THANK YOU again
    Bob
     
  17. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    It's no problem at all.
    Anything to help.

    Run the system for a couple of days and see how it goes.
    Then let us know if the problem has been cured.
    If not, we'll look a bit more.
     
  18. bob12a

    bob12a Senior Member

    Joined:
    Aug 14, 2009
    Messages:
    857
    Location:
    uk
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MEDIONPC MS-7204
    CPU:
    3.00 gigahertz Intel Pentium D 16 kilobyte primary memory cache 1024 kilobyte secondary memory cache
    Memory:
    3072 Megabytes Installed Memory Slot 'A0' has 512 MB Slot 'A1' has 512 MB Slot 'A2' has 512 MB Sl
    Hard Drive:
    910.14 Gigabytes Usable Hard Drive Capacity 376.83 Gigabytes Hard Drive Free Space
    Power Supply:
    NVIDIA GeForce 6700 XL [Display adapter] Samsung SyncMaster [Monitor] (22.0"vis, s/n HS2P405617, A
    Microsoft's newly released beta version of Windows Defender Offline For information I know nothing about this but you might like to do a google search I read about it in windows secrets.


    PS had error 138 turn up again just once
    Just had my left eye operated on catarac replaced not feeling to bad
    Bob
     
  19. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Cataracts can be a sign of above average sugar levels, Bob.
     
  20. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Bob,

    Get well soon then and don't feel you have to rush to post.
    Post when you feel better.

    How does this compare to previously .... was the error more frequent before?

    When you feel ready we can run other scans which maybe able to identify whatever is happening.
     

Share This Page