I have tried the msconfig thingy but it didn't work ,also restoring my BIOS to the default
please help...
OTL logfile created on: 3/21/2013 8:11:03 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ramius\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.74% Memory free
3.98 Gb Paging File | 3.13 Gb Available in Paging File | 78.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 244.14 Gb Total Space | 172.46 Gb Free Space | 70.64% Space Free | Partition Type: NTFS
Drive D: | 221.61 Gb Total Space | 219.92 Gb Free Space | 99.24% Space Free | Partition Type: NTFS
Computer Name: RAMIUS-PC | User Name: Ramius | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/21 08:10:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ramius\Downloads\OTL.scr
PRC - [2013/03/21 08:08:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ramius\Downloads\OTL.exe
PRC - [2013/03/16 08:59:42 | 005,852,440 | ---- | M] (Pokki) -- C:\Users\Ramius\AppData\Local\Pokki\Engine\pokki.exe
PRC - [2013/03/14 12:50:41 | 000,894,308 | ---- | M] (JamesR) -- C:\Users\Ramius\Downloads\Le Bot 6.4.exe
PRC - [2013/03/11 08:22:07 | 001,274,320 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2009/10/31 13:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 09:14:21 | 000,497,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\HelpPane.exe
========== Modules (No Company Name) ==========
MOD - [2013/03/20 07:08:15 | 004,537,856 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.3.0\libglesv2.dll
MOD - [2013/03/20 07:08:15 | 000,100,864 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.3.0\libegl.dll
MOD - [2013/03/16 08:59:44 | 001,294,616 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Pokki\ocdeskband_0.dll
MOD - [2013/03/16 08:56:08 | 000,061,952 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Pokki\Engine\chrome.dll
MOD - [2013/03/11 08:22:06 | 000,459,728 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\25.0.1364.172\ppgooglenaclpluginchrome.dll
MOD - [2013/03/11 08:22:05 | 012,662,224 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
MOD - [2013/03/11 08:22:04 | 004,050,896 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\25.0.1364.172\pdf.dll
MOD - [2013/03/11 08:21:16 | 001,552,848 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\25.0.1364.172\ffmpegsumo.dll
MOD - [2012/12/06 06:23:48 | 000,184,846 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Pokki\Engine\avformat-53.dll
MOD - [2012/12/06 06:23:44 | 001,093,646 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Pokki\Engine\avcodec-53.dll
MOD - [2012/12/06 06:23:44 | 000,117,262 | ---- | M] () -- C:\Users\Ramius\AppData\Local\Pokki\Engine\avutil-51.dll
MOD - [2010/01/21 17:34:10 | 008,793,952 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/01/10 12:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Norton Internet Security\Engine\20.3.0.36\ccSvcHst.exe /s NIS /m C:\Program Files\Norton Internet Security\Engine\20.3.0.36\diMaster.dll /prefetch:1 -- (NIS)
SRV - [2013/03/20 21:28:41 | 000,107,520 | ---- | M] () [Disabled | Stopped] -- C:\Users\Ramius\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe -- (DefaultTabUpdate)
SRV - [2013/02/11 15:42:26 | 000,572,928 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\DefaultTab\DefaultTabSearch.exe -- (DefaultTabSearch)
SRV - [2013/02/01 10:44:29 | 000,269,480 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013/02/01 10:44:29 | 000,136,360 | ---- | M] (Avira GmbH) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013/01/30 06:29:00 | 000,188,760 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe -- (IB Updater)
SRV - [2013/01/26 00:58:02 | 002,663,976 | ---- | M] (Iminent) [Disabled | Stopped] -- C:\Program Files\Common Files\Umbrella\Umbrella.exe -- (SProtection)
SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/20 04:10:58 | 001,699,168 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2012/09/12 02:27:58 | 000,435,016 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2012/04/04 13:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/02/07 15:49:38 | 000,148,024 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\TuneUp360\CareMon.exe -- (CareMon)
SRV - [2011/04/02 02:30:04 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/03/22 16:37:16 | 000,497,480 | ---- | M] (Splashtop Inc.) [Disabled | Stopped] -- C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe -- (WCUService_STC_IE)
SRV - [2011/02/08 11:39:44 | 000,603,904 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2011/02/08 11:12:08 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2011/02/08 11:11:36 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2011/02/08 11:11:06 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service)
SRV - [2010/09/03 09:01:36 | 000,125,216 | ---- | M] (DeviceVM, Inc.) [Disabled | Stopped] -- C:\Program Files\DeviceVM\SmartView\SmartViewService.exe -- (SmartViewService)
SRV - [2010/02/03 03:18:22 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/01/22 09:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/01/15 20:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/11/26 07:42:18 | 000,583,640 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2009/07/21 03:51:52 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009/07/14 09:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/02/23 11:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Disabled | Stopped] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2008/11/26 03:58:39 | 000,081,920 | R--- | M] () [Disabled | Stopped] -- C:\Windows\System32\SupportAppXL\cdrom_mon.exe -- (Autorun CDROM Monitor)
SRV - [2008/11/10 04:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
DRV - [2013/02/07 10:14:31 | 001,603,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130219.024\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/02/07 10:14:31 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/02/07 10:14:31 | 000,093,296 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130219.024\NAVENG.SYS -- (NAVENG)
DRV - [2013/02/06 13:59:19 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/02/06 08:44:54 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130216.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/02/01 10:44:29 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013/02/01 10:44:29 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013/01/31 11:18:18 | 000,338,592 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\NIS\1403000.024\symnets.sys -- (SymNetS)
DRV - [2013/01/31 11:18:06 | 000,934,488 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\symefa.sys -- (SymEFA)
DRV - [2013/01/29 09:45:18 | 000,602,712 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\NIS\1403000.024\srtsp.sys -- (SRTSP)
DRV - [2013/01/29 09:45:18 | 000,032,344 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\NIS\1403000.024\srtspx.sys -- (SRTSPX)
DRV - [2013/01/22 10:15:32 | 000,367,704 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1403000.024\symds.sys -- (SymDS)
DRV - [2013/01/16 19:22:36 | 000,997,464 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130208.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/12/14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/11/16 10:22:01 | 000,175,264 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\NIS\1403000.024\ironx86.sys -- (SymIRON)
DRV - [2012/11/16 10:18:04 | 000,134,304 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\NIS\1403000.024\ccsetx86.sys -- (ccSet_NIS)
DRV - [2012/09/19 08:02:02 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/06/18 06:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/11/25 21:02:46 | 001,108,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/10/14 12:07:32 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/10/14 12:07:20 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/10/14 12:07:06 | 000,105,088 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/07/14 09:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/14 09:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 09:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/14 07:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/14 07:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 07:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim....B-002522872F47}
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD22}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKLM\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = http://start.iminent...q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweeti...B-002522872F47}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-sea...000002522872f47
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.b1.org...xr&chid=c162341
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page Before = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.iminent...E9-C8DCBFC233FB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Before = http://search.softon...chSource=10&cc=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\URLSearchHook: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No CLSID value found
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-sea...000002522872f47
IE - HKCU\..\SearchScopes\{18490122-A3DD-467F-AFC1-6156E463F5EC}: "URL" = http://search.softon...rce=4&cc=&r=671
IE - HKCU\..\SearchScopes\{588CFEA1-3FD6-4b6c-867A-9839F6C0A40E}: "URL" = http://www.google.co...q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://search.yahoo....icevm&type=ASRK
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.se...ct=sb&qsrc=2869
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKCU\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = http://start.iminent...q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...6Oz1vrGntw&i=26
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweeti...B-002522872F47}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Delta Search"
FF - prefs.js..browser.search.selectedEngine: "Delta Search"
FF - prefs.js..browser.startup.homepage: "http://www.delta-sea...00002522872f47"
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.4
FF - prefs.js..extensions.enabledItems: [email protected]:1.5.0
FF - prefs.js..extensions.enabledItems: {C9B68337-E93A-44EA-94DC-CB300EC06444}:5.30.4
FF - prefs.js..extensions.enabledItems: {FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}:2.0.0.574
FF - prefs.js..extensions.enabledItems: [email protected]:6.10.2.1
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1,S: S", ""
FF - prefs.js..browser.search.defaultenginename,S: S", ""
FF - prefs.js..browser.search.selectedEngine,S: S", ""
FF - prefs.js..keyword.URL: "http://dts.search-re...&o=APN10641&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - prefs.js..browser.startup.homepage: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Pure Codec\Real\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2629: C:\Program Files\Pure Codec\Real\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Pure Codec\Real\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@eximion.com/KalydoPlayer: C:\Users\Ramius\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ramius\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Ramius\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\pokki.com/PokkiDownloadHelper: C:\Users\Ramius\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll (Pokki)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/02/09 00:22:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/02/09 00:22:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox [2013/03/01 08:01:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFFPlgn\ [2013/02/06 13:59:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn\ [2013/03/19 22:06:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\IB Updater\Firefox [2013/03/01 08:01:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Iminent\[email protected] [2013/03/13 10:51:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/21 02:30:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/12 03:49:08 | 000,000,000 | ---D | M]
[2013/01/28 12:55:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramius\AppData\Roaming\mozilla\Extensions
[2013/03/20 22:45:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions
[2013/01/28 12:55:36 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{15a0413e-9f45-4d45-9a75-2c20b15b5b51}
[2013/03/20 22:44:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
[2011/02/08 22:58:32 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/02/08 22:36:05 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2013/03/13 10:51:18 | 000,000,000 | ---D | M] (IMinent Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
[2013/01/28 02:35:25 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2013/01/27 14:38:33 | 000,000,000 | ---D | M] (SweetPacks Toolbar for Firefox) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2013/03/20 21:28:40 | 000,000,000 | ---D | M] (Default Tab) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2011/02/08 22:36:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2013/01/27 14:55:36 | 000,000,000 | ---D | M] (Babylon Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2013/03/03 13:32:08 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2013/01/28 02:22:16 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2013/01/28 02:39:03 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\Ramius\AppData\Roaming\mozilla\Firefox\Profiles\dc3aozrz.default\extensions\[email protected]
[2013/01/27 14:55:37 | 000,002,422 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\babylon1.xml
[2013/03/06 07:13:57 | 000,006,484 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\BrowserProtect.xml
[2011/02/08 22:36:06 | 000,000,913 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\conduit.xml
[2013/03/06 07:14:14 | 000,001,294 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\delta.xml
[2013/01/28 02:20:20 | 000,002,203 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\MyStart Search.xml
[2013/03/20 22:45:05 | 000,001,977 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\search-here.xml
[2013/01/28 12:55:27 | 000,002,679 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\Search_Results.xml
[2013/02/04 07:53:49 | 000,002,060 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\softonic.xml
[2013/01/27 14:39:05 | 000,003,998 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\mozilla\firefox\profiles\dc3aozrz.default\searchplugins\sweetim.xml
[2013/02/04 07:53:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/08 23:00:05 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011/02/09 00:22:02 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2011/02/09 00:22:02 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2013/03/01 08:01:08 | 000,000,000 | ---D | M] (IB Updater) -- C:\PROGRAM FILES\IB UPDATER\FIREFOX
[2013/03/13 10:51:51 | 000,000,000 | ---D | M] ("Iminent Minibar") -- C:\PROGRAM FILES\IMINENT\[email protected]
[2013/03/06 07:13:57 | 000,006,484 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2013/01/28 12:55:27 | 000,002,679 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2013/01/11 05:08:36 | 000,002,147 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\StartWeb.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com.ph/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: DivX OVS Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Pure Codec\Real\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Pure Codec\Real\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Pure Codec\Real\Netscape6\nprpjplug.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Ramius\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - Extension: Entanglement = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Crash Bandicoot Online = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\copoaaffjmndhhefnhlaehnhjkdjaecm\1_0\
CHR - Extension: PicMonkey = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm\1.5_0\
CHR - Extension: DivX HiQ = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: Muzy = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\jammhkdcdlocifampbainkfchnoneahm\1.0.5_0\
CHR - Extension: KIDO'Z TV = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\jokdeafnhahffanabnbjjjjmoechjklc\2.2_0\
CHR - Extension: Break The Wall = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\klhfgnobmdkblmbdahcnpajbjnfmknpn\1.5_0\
CHR - Extension: Poppit = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Need for Speed World = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk\1.0.0.4_0\
CHR - Extension: Pop Art Studio Online = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\oompiimecpnflklhlnmdpddcjdmiibkf\1.0.0.0_0\
CHR - Extension: Instagram for Chrome = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb\4.1_0\
CHR - Extension: Entanglement = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Crash Bandicoot Online = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\copoaaffjmndhhefnhlaehnhjkdjaecm\1_0\
CHR - Extension: PicMonkey = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm\1.5_0\
CHR - Extension: DivX HiQ = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: Muzy = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\jammhkdcdlocifampbainkfchnoneahm\1.0.5_0\
CHR - Extension: KIDO'Z TV = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\jokdeafnhahffanabnbjjjjmoechjklc\2.2_0\
CHR - Extension: Break The Wall = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\klhfgnobmdkblmbdahcnpajbjnfmknpn\1.5_0\
CHR - Extension: Poppit = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Need for Speed World = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk\1.0.0.4_0\
CHR - Extension: Pop Art Studio Online = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\oompiimecpnflklhlnmdpddcjdmiibkf\1.0.0.0_0\
CHR - Extension: Instagram for Chrome = C:\Users\Ramius\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb\4.1_0\
O1 HOSTS File: ([2009/06/11 05:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SmartView VisualBookmark) - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files\DeviceVM\SmartView\SmartView.dll (DeviceVM, Inc.)
O2 - BHO: (Search-Results Toolbar) - {15a0413e-9f45-4d45-9a75-2c20b15b5b51} - Reg Error: Value error. File not found
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - Reg Error: Value error. File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IB Updater) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll ()
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.3.0.36\coIEPlg.dll File not found
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.3.0.36\IPS\IPSBHO.DLL File not found
O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Ramius\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - Reg Error: Value error. File not found
O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly Technologies Ltd)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (DataMngr) - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - Reg Error: Value error. File not found
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Softonic Helper Object) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - Reg Error: Value error. File not found
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {15a0413e-9f45-4d45-9a75-2c20b15b5b51} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.3.0.36\coIEPlg.dll File not found
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.3.0.36\coIEPlg.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A28DD1DD-8481-4D4A-BFD4-0422F5679556}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~2\Wincert\WIN32C~1.DLL) - C:\ProgramData\Wincert\win32cert.dll ()
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261184~1.107\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1184.107\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
O20 - AppInit_DLLs: (c:\progra~1\zoomex\sprote~1.dll) - c:\Program Files\ZoomEx\sprotector.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{c8aaf3f3-3415-11e0-ab9f-002522872f47}\Shell - "" = AutoRun
O33 - MountPoints2\{c8aaf3f3-3415-11e0-ab9f-002522872f47}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/20 21:28:44 | 000,000,000 | ---D | C] -- C:\Program Files\DefaultTab
[2013/03/20 21:28:41 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\DefaultTab
[2013/03/20 21:28:24 | 000,000,000 | ---D | C] -- C:\ProgramData\IBUpdaterService
[2013/03/20 17:37:09 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\spotmau
[2013/03/20 16:34:18 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp360
[2013/03/20 16:34:16 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp360
[2013/03/20 07:26:06 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/03/20 06:17:15 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Malwarebytes
[2013/03/20 06:17:09 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/03/20 06:17:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/20 06:17:09 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/03/20 06:17:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/03/20 06:16:51 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Local\Programs
[2013/03/18 15:21:34 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Optimizer Pro
[2013/03/13 11:35:18 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Iminent
[2013/03/13 11:34:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Iminent
[2013/03/13 11:33:00 | 000,000,000 | ---D | C] -- C:\Temp
[2013/03/13 10:51:28 | 000,000,000 | ---D | C] -- C:\Program Files\IMinent Toolbar
[2013/03/13 10:50:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Umbrella
[2013/03/13 10:50:26 | 000,000,000 | ---D | C] -- C:\Program Files\Iminent
[2013/03/13 10:47:22 | 000,000,000 | ---D | C] -- C:\Program Files\Gophoto.it
[2013/03/13 09:05:55 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\LolClient
[2013/03/12 15:54:23 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\GarenaPlus
[2013/03/12 15:43:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena
[2013/03/12 15:43:16 | 000,000,000 | ---D | C] -- C:\Program Files\Garena Plus
[2013/03/12 15:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\GarenaLoLPH
[2013/03/12 15:42:07 | 000,000,000 | ---D | C] -- C:\ProgramData\GarenaMessenger
[2013/03/12 09:11:03 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Local\Garena
[2013/03/06 07:36:05 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013/03/06 07:13:18 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\GoforFiles
[2013/03/04 07:45:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013/03/04 07:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013/03/04 07:44:13 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013/03/03 13:32:07 | 000,000,000 | ---D | C] -- C:\Program Files\Delta
[2013/03/03 13:32:02 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Delta
[2013/03/03 02:56:15 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\skypePM
[2013/03/03 00:56:08 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\ExpressFiles
[2013/03/03 00:56:08 | 000,000,000 | ---D | C] -- C:\Program Files\ExpressFiles
[2013/02/28 05:05:16 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Local\CrashDumps
[2013/02/26 08:13:25 | 000,000,000 | ---D | C] -- C:\logs
[2013/02/26 08:13:13 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Chikka Messenger
[2013/02/24 11:11:02 | 000,000,000 | ---D | C] -- C:\Users\Ramius\Documents\CrazyCarScreenShot
[2013/02/24 11:07:00 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\Kalydo
[2013/02/21 15:38:39 | 000,000,000 | ---D | C] -- C:\Windows\System32\Extensions
[2013/02/21 15:38:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\searchplugins
[2013/02/20 23:03:26 | 000,000,000 | ---D | C] -- C:\Users\Ramius\AppData\Roaming\dvdcss
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/21 07:46:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/03/21 07:46:48 | 1602,985,984 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/20 22:43:40 | 000,000,884 | RHS- | M] () -- C:\Users\Ramius\ntuser.pol
[2013/03/20 22:43:21 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/20 22:43:21 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/20 22:43:18 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/20 22:43:17 | 000,000,364 | -H-- | M] () -- C:\Windows\tasks\ZoomExUpdaterTask{A8AEE48D-D3ED-4E48-8EDA-A7715A454B59}.job
[2013/03/20 21:29:32 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\PC Performer.job
[2013/03/20 18:00:10 | 000,111,469 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\userenv.xml.urlencode
[2013/03/20 18:00:09 | 000,083,046 | ---- | M] () -- C:\Users\Ramius\AppData\Roaming\userenv.xml
[2013/03/20 17:31:23 | 000,626,844 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/03/20 17:31:23 | 000,107,160 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/03/20 16:34:18 | 000,000,232 | ---- | M] () -- C:\Windows\tasks\TuneUp360 Reminder.job
[2013/03/20 06:17:09 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/19 23:09:20 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/19 22:05:13 | 000,001,388 | ---- | M] () -- C:\Users\Ramius\Desktop\Games.lnk
[2013/03/15 14:10:19 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/14 11:38:05 | 000,000,480 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Ramius.job
[2013/03/13 11:34:54 | 000,000,596 | ---- | M] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013/03/12 15:53:38 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\League of Legends.lnk
[2013/03/12 15:43:39 | 000,001,021 | ---- | M] () -- C:\Users\Public\Desktop\Garena Plus.lnk
[2013/03/04 16:58:40 | 000,028,160 | ---- | M] () -- C:\Windows\System32\ImHttpComm.dll
[2013/03/03 02:56:24 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2013/02/28 04:32:04 | 000,927,533 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1403000.024\Cat.DB
[2013/02/28 04:31:55 | 000,014,818 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1403000.024\VT20130115.021
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/20 22:27:10 | 000,000,884 | RHS- | C] () -- C:\Users\Ramius\ntuser.pol
[2013/03/20 21:28:20 | 000,000,390 | ---- | C] () -- C:\Windows\tasks\PC Performer.job
[2013/03/20 18:00:10 | 000,111,469 | ---- | C] () -- C:\Users\Ramius\AppData\Roaming\userenv.xml.urlencode
[2013/03/20 17:37:06 | 000,083,046 | ---- | C] () -- C:\Users\Ramius\AppData\Roaming\userenv.xml
[2013/03/20 16:34:18 | 000,000,232 | ---- | C] () -- C:\Windows\tasks\TuneUp360 Reminder.job
[2013/03/20 06:17:09 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/13 11:34:46 | 000,000,596 | ---- | C] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013/03/12 15:53:35 | 000,001,011 | ---- | C] () -- C:\Users\Public\Desktop\League of Legends.lnk
[2013/03/12 15:43:37 | 000,001,021 | ---- | C] () -- C:\Users\Public\Desktop\Garena Plus.lnk
[2013/03/03 02:56:24 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2013/02/21 21:59:58 | 000,001,388 | ---- | C] () -- C:\Users\Ramius\Desktop\Games.lnk
[2013/01/28 02:49:22 | 000,028,160 | ---- | C] () -- C:\Windows\System32\ImHttpComm.dll
[2011/10/07 11:06:34 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/04/21 02:59:37 | 000,000,094 | -H-- | C] () -- C:\Windows\System32\spv1_WCssg.ini
[2011/04/20 05:54:24 | 000,000,040 | ---- | C] () -- C:\Windows\RSoftInfo.dat
[2011/04/05 04:51:27 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2011/03/07 12:40:28 | 000,003,584 | ---- | C] () -- C:\Users\Ramius\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/09 15:58:32 | 000,000,171 | ---- | C] () -- C:\Users\Ramius\AppData\Roaming\default.rss
[2011/02/08 11:19:04 | 000,000,406 | RHS- | C] () -- C:\ProgramData\ntuser.pol
========== ZeroAccess Check ==========
[2009/07/14 12:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/07/27 22:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 09:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 09:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/02/18 11:05:39 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\B1Toolbar
[2013/01/27 14:57:34 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\BabSolution
[2013/01/27 14:52:46 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Babylon
[2013/02/26 08:13:13 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Chikka Messenger
[2013/03/20 21:28:41 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\DefaultTab
[2013/03/03 13:32:02 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Delta
[2011/02/08 11:13:53 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\DeviceVm
[2011/10/08 12:08:23 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\EA
[2011/02/13 01:04:01 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\EPSON
[2013/03/03 00:56:16 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\ExpressFiles
[2011/04/21 12:26:34 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\funkitron
[2013/03/19 22:16:01 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\GarenaPlus
[2013/03/06 07:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\GoforFiles
[2013/03/05 14:12:00 | 000,000,000 | -H-D | M] -- C:\Users\Ramius\AppData\Roaming\IFViewer
[2013/03/13 11:35:18 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Iminent
[2011/04/20 04:20:47 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Incredible Ink
[2011/02/08 11:44:11 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Jetdogs Studios
[2013/02/24 11:07:00 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Kalydo
[2011/02/09 00:22:04 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Local
[2013/03/13 09:05:55 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\LolClient
[2013/01/28 12:55:23 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\MusicNet
[2013/03/18 15:21:34 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Optimizer Pro
[2011/02/08 11:55:30 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\PlayFirst
[2012/12/08 12:43:25 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Registry Mechanic
[2013/01/25 09:30:23 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Rovio
[2013/02/04 07:53:21 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Softonic
[2013/03/20 17:37:09 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\spotmau
[2013/03/20 17:30:39 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\TeraCopy
[2013/01/28 02:18:58 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\TuneUp Software
[2013/01/30 10:29:09 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Ulead Systems
[2013/01/27 16:46:54 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Unity
[2013/03/20 22:26:42 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\uTorrent
[2013/01/11 12:37:08 | 000,000,000 | ---D | M] -- C:\Users\Ramius\AppData\Roaming\Wildfire
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C6EBC69
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:0C988F7D
< End of report >
Edited by ramiusify, 20 March 2013 - 06:41 PM.