========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files (x86)\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG8\Toolbar\Firefox\avg@igeared
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/15 13:50:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/08/17 10:23:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{699C5557-0574-11E2-8271-B8AC6F996F26}: C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}\ [2012/09/23 07:47:17 | 000,000,000 | ---D | M]
[2009/12/26 11:40:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Extensions
[2012/09/21 11:38:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions
[2012/06/24 21:14:43 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\ffxtlbr@incredibar.com
[2012/06/24 21:14:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Adblock) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Bandwidth Tester) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{7C06F9C2-B0D0-47b4-93B8-116C919084BA}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (AutoForm) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fa908322-0757-4eb2-9427-dca5567ac7a7}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fb0cbf5b-695b-4322-8b49-5dedbfb946fc}
[2012/06/24 21:14:42 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\ffxtlbr@incredibar.com
[2009/12/26 11:33:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\temp
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{dc0fa13d-3daf-73ec-e852-912722c85309}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{f35b2da4-cece-d4e8-0bad-ccd1df7ee17a}
[2012/07/06 13:19:24 | 000,148,816 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\autofillForms@blueimp.net.xpi
[2012/07/02 08:26:45 | 002,265,909 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\firefox@tvunetworks.com.xpi
[2012/07/02 08:22:38 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/07/02 08:20:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/12/18 21:23:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
[2012/09/23 07:47:17 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\BLUESMAN\APPDATA\LOCAL\{699C5557-0574-11E2-8271-B8AC6F996F26}
[2012/09/15 13:50:56 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/18 21:11:31 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/09/15 13:50:54 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/20 18:03:28 | 000,002,024 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/09/15 13:50:54 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://mystart.incredibar.com/mb161?a=6PQBuVHlh7&I=26
CHR - Extension: No name found = C:\Users\Bluesman\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
O1 HOSTS File: ([2012/09/26 13:50:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid, Inc. All rights reserved.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-4292630620-794784561-241906710-1000..\Run: [PhotoshopElements8SyncAgent] C:\Program Files (x86)\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bluesman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk = C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..Trusted Domains: ([]msn in Computer)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0/2/f02b515c-7076-4cee-bc08-fd6fea594578/VirtualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Reg Error: Key error.)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://protect.microsoft.com/security/protect/wsa/shared/CAB/x86/msSecAdv.cab?1102267634347 (MSSecurityAdvisor Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} https://www.webiqonline.com/WebIQ/bin/WebIQ.cab (Reg Error: Key error.)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1102266753391 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147379248038 (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://69.177.83.150/activex/AxisCamControl.cab (CamImage Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_06-windows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://avptcam.uconn.edu/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Poker http://download.games.yahoo.com/games/clients/y/pt1_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 156.154.119.11 156.154.129.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{61228E68-0127-43F1-8400-0DF616A8938F}: DhcpNameServer = 156.154.119.11 156.154.129.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8355ABA-5B16-474E-B856-3B41D981710F}: DhcpNameServer = 156.154.119.11 156.154.129.11
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\sysimage - No CLSID value found
O18:64bit: - Protocol\Handler\wia - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
O18:64bit: - Protocol\Filter\lzdhtml - No CLSID value found
O18 - Protocol\Filter\lzdhtml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/26 14:24:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bluesman\Desktop\OTL.exe
[2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\NetworkService\AppData\Local\temp
[2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\LocalService\AppData\Local\temp
[2012/09/26 13:50:14 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/09/26 13:42:20 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/26 13:28:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/26 13:28:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/26 13:28:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/26 13:20:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/26 13:20:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/26 13:14:24 | 004,757,076 | R--- | C] (Swearware) -- C:\Users\Bluesman\Desktop\ComboFix.exe
[2012/09/26 06:31:50 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Bluesman\Desktop\aswMBR.exe
[2012/09/26 06:20:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\RK_Quarantine
[2012/09/26 01:27:27 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/25 17:31:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
[2012/09/25 05:43:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/25 05:43:03 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/25 05:43:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/25 05:42:03 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Bluesman\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/25 05:35:27 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Malwarebytes
[2012/09/25 05:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/25 05:28:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{968259CE-CF08-41BC-94BE-2FDAB779FE06}
[2012/09/24 15:37:35 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Bluesman\Desktop\TDSSKiller.exe
[2012/09/24 15:37:35 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\tdsskiller
[2012/09/24 14:26:42 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{6735502A-4CFA-4455-8859-6F91ABA096F3}
[2012/09/23 19:44:11 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{D8E63098-088A-4EAF-A65F-5605B3AF8164}
[2012/09/23 08:22:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/09/23 08:22:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/09/23 07:52:07 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/09/23 07:47:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}
[2012/09/20 12:53:32 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{844A71EC-7437-43BF-84B3-D03643DF0F5F}
[2012/09/19 12:46:46 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0F5B6F81-50DF-4FBC-9C75-A63D7445ACF6}
[2012/09/16 04:09:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{ADE0C4BA-3661-4C42-B54B-C062DAD95CCC}
[2012/09/15 16:04:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/09/15 16:03:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/09/15 14:29:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
[2012/09/15 14:29:09 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\SystemRequirementsLab
[2012/09/15 10:13:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012/09/15 10:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2012/09/15 10:10:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2012/09/15 10:10:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2012/09/15 10:04:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{C517D045-4AB9-4A87-99AE-232699B81B41}
[2012/09/14 12:54:59 | 000,255,352 | ---- | C] (Audible, Inc.) -- C:\Windows\SysWow64\awrdscdc.ax
[2012/09/14 12:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Audible
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Documents\Audible
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audible
[2012/09/14 11:45:19 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{17A2073C-C4B4-42EF-A3DD-41854554AF43}
[2012/09/13 14:37:41 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8459B45-BD30-4F96-8429-8F7CE5FDAE7F}
[2012/09/13 13:38:09 | 000,604,672 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2012/09/13 13:37:27 | 012,350,464 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idtcpl64.cpl
[2012/09/13 13:37:27 | 000,564,224 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idt64mp1.exe
[2012/09/13 13:37:27 | 000,456,192 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe
[2012/09/13 13:37:26 | 003,738,112 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll
[2012/09/13 13:35:33 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2012/09/13 10:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
[2012/09/13 10:45:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Device Center
[2012/09/11 14:20:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{467F4BB2-FF87-42ED-ACFA-54B14AA518EB}
[2012/09/10 13:33:31 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8FC8CF5-54BF-4C66-8084-29901FB5F97A}
[2012/09/09 08:36:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{9298516F-C007-4518-85C5-0A6869298A60}
[2012/09/08 10:55:44 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{DDAB4F53-E743-4F8C-B3D4-91C31D564C0A}
[2012/09/07 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EB402655-03EE-4595-ADDD-CF4B66C57A6A}
[2012/09/05 12:33:15 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EE70D068-5A23-4462-974B-D945F751C6FF}
[2012/09/04 13:25:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8B55E16-14EE-43DE-B8F4-D0D2C3015A5B}
[2012/09/03 20:02:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0569FBA8-3704-4C42-AC57-F4D1059AE728}
[2012/08/31 11:55:12 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FA24B57A-518F-4599-8128-9C8FF5C0B0D7}
[2012/08/30 09:38:37 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FEB68387-36A9-4B5B-9902-59FDC13B18E3}
[2012/08/29 12:56:54 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{8F7A452B-E58E-4B17-9EE2-68B3FAB59969}
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/10/12 13:35:45 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files (x86)\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bluesman\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG8\Toolbar\Firefox\avg@igeared
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/06/24 21:14:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/15 13:50:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/08/17 10:23:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/25 09:20:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{699C5557-0574-11E2-8271-B8AC6F996F26}: C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}\ [2012/09/23 07:47:17 | 000,000,000 | ---D | M]
[2009/12/26 11:40:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Extensions
[2012/09/21 11:38:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions
[2012/06/24 21:14:43 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\ffxtlbr@incredibar.com
[2012/06/24 21:14:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Adblock) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Bandwidth Tester) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{7C06F9C2-B0D0-47b4-93B8-116C919084BA}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (AutoForm) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fa908322-0757-4eb2-9427-dca5567ac7a7}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\{fb0cbf5b-695b-4322-8b49-5dedbfb946fc}
[2012/06/24 21:14:42 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\ffxtlbr@incredibar.com
[2009/12/26 11:33:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\f8iip4f0.default\extensions\temp
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{dc0fa13d-3daf-73ec-e852-912722c85309}
[2009/12/26 11:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\z15kh4bz.default\extensions\{f35b2da4-cece-d4e8-0bad-ccd1df7ee17a}
[2012/07/06 13:19:24 | 000,148,816 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\autofillForms@blueimp.net.xpi
[2012/07/02 08:26:45 | 002,265,909 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\firefox@tvunetworks.com.xpi
[2012/07/02 08:22:38 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Bluesman\AppData\Roaming\Mozilla\Firefox\Profiles\cmzlwot0.Rich\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/07/02 08:20:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/12/18 21:23:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com
[2012/09/23 07:47:17 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\BLUESMAN\APPDATA\LOCAL\{699C5557-0574-11E2-8271-B8AC6F996F26}
[2012/09/15 13:50:56 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/18 21:11:31 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/09/15 13:50:54 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/20 18:03:28 | 000,002,024 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/09/15 13:50:54 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://mystart.incredibar.com/mb161?a=6PQBuVHlh7&I=26
CHR - Extension: No name found = C:\Users\Bluesman\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
O1 HOSTS File: ([2012/09/26 13:50:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files (x86)\Freecorder\tbFree.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid, Inc. All rights reserved.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-4292630620-794784561-241906710-1000..\Run: [PhotoshopElements8SyncAgent] C:\Program Files (x86)\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bluesman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk = C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-4292630620-794784561-241906710-1000\..Trusted Domains: ([]msn in Computer)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0/2/f02b515c-7076-4cee-bc08-fd6fea594578/VirtualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Reg Error: Key error.)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://protect.microsoft.com/security/protect/wsa/shared/CAB/x86/msSecAdv.cab?1102267634347 (MSSecurityAdvisor Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} https://www.webiqonline.com/WebIQ/bin/WebIQ.cab (Reg Error: Key error.)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1102266753391 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147379248038 (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://69.177.83.150/activex/AxisCamControl.cab (CamImage Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_06-windows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://avptcam.uconn.edu/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Poker http://download.games.yahoo.com/games/clients/y/pt1_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 156.154.119.11 156.154.129.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{61228E68-0127-43F1-8400-0DF616A8938F}: DhcpNameServer = 156.154.119.11 156.154.129.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8355ABA-5B16-474E-B856-3B41D981710F}: DhcpNameServer = 156.154.119.11 156.154.129.11
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\sysimage - No CLSID value found
O18:64bit: - Protocol\Handler\wia - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\Windows\SysWOW64\wiascr.dll File not found
O18:64bit: - Protocol\Filter\lzdhtml - No CLSID value found
O18 - Protocol\Filter\lzdhtml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\SysWOW64\ExplorerFrame.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\Bluesman\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/26 14:24:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bluesman\Desktop\OTL.exe
[2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\NetworkService\AppData\Local\temp
[2012/09/26 13:59:45 | 000,000,000 | ---D | C] -- C:\Users\LocalService\AppData\Local\temp
[2012/09/26 13:50:14 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/09/26 13:42:20 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/26 13:28:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/26 13:28:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/26 13:28:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/26 13:20:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/26 13:20:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/26 13:14:24 | 004,757,076 | R--- | C] (Swearware) -- C:\Users\Bluesman\Desktop\ComboFix.exe
[2012/09/26 06:31:50 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Bluesman\Desktop\aswMBR.exe
[2012/09/26 06:20:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\RK_Quarantine
[2012/09/26 01:27:27 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/25 17:31:29 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
[2012/09/25 05:43:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/25 05:43:03 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/25 05:43:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/25 05:42:03 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Bluesman\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/25 05:35:27 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Malwarebytes
[2012/09/25 05:35:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/25 05:28:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{968259CE-CF08-41BC-94BE-2FDAB779FE06}
[2012/09/24 15:37:35 | 002,212,440 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Bluesman\Desktop\TDSSKiller.exe
[2012/09/24 15:37:35 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Desktop\tdsskiller
[2012/09/24 14:26:42 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{6735502A-4CFA-4455-8859-6F91ABA096F3}
[2012/09/23 19:44:11 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{D8E63098-088A-4EAF-A65F-5605B3AF8164}
[2012/09/23 08:22:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/09/23 08:22:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/09/23 07:52:07 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/09/23 07:47:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{699C5557-0574-11E2-8271-B8AC6F996F26}
[2012/09/20 12:53:32 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{844A71EC-7437-43BF-84B3-D03643DF0F5F}
[2012/09/19 12:46:46 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0F5B6F81-50DF-4FBC-9C75-A63D7445ACF6}
[2012/09/16 04:09:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{ADE0C4BA-3661-4C42-B54B-C062DAD95CCC}
[2012/09/15 16:04:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/09/15 16:03:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/09/15 14:29:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
[2012/09/15 14:29:09 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\SystemRequirementsLab
[2012/09/15 10:13:26 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012/09/15 10:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2012/09/15 10:10:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2012/09/15 10:10:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2012/09/15 10:04:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{C517D045-4AB9-4A87-99AE-232699B81B41}
[2012/09/14 12:54:59 | 000,255,352 | ---- | C] (Audible, Inc.) -- C:\Windows\SysWow64\awrdscdc.ax
[2012/09/14 12:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Audible
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\Documents\Audible
[2012/09/14 12:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audible
[2012/09/14 11:45:19 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{17A2073C-C4B4-42EF-A3DD-41854554AF43}
[2012/09/13 14:37:41 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8459B45-BD30-4F96-8429-8F7CE5FDAE7F}
[2012/09/13 13:38:09 | 000,604,672 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2012/09/13 13:37:27 | 012,350,464 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idtcpl64.cpl
[2012/09/13 13:37:27 | 000,564,224 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idt64mp1.exe
[2012/09/13 13:37:27 | 000,456,192 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe
[2012/09/13 13:37:26 | 003,738,112 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll
[2012/09/13 13:35:33 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2012/09/13 10:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
[2012/09/13 10:45:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Device Center
[2012/09/11 14:20:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{467F4BB2-FF87-42ED-ACFA-54B14AA518EB}
[2012/09/10 13:33:31 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8FC8CF5-54BF-4C66-8084-29901FB5F97A}
[2012/09/09 08:36:36 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{9298516F-C007-4518-85C5-0A6869298A60}
[2012/09/08 10:55:44 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{DDAB4F53-E743-4F8C-B3D4-91C31D564C0A}
[2012/09/07 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EB402655-03EE-4595-ADDD-CF4B66C57A6A}
[2012/09/05 12:33:15 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{EE70D068-5A23-4462-974B-D945F751C6FF}
[2012/09/04 13:25:25 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{A8B55E16-14EE-43DE-B8F4-D0D2C3015A5B}
[2012/09/03 20:02:17 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{0569FBA8-3704-4C42-AC57-F4D1059AE728}
[2012/08/31 11:55:12 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FA24B57A-518F-4599-8128-9C8FF5C0B0D7}
[2012/08/30 09:38:37 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{FEB68387-36A9-4B5B-9902-59FDC13B18E3}
[2012/08/29 12:56:54 | 000,000,000 | ---D | C] -- C:\Users\Bluesman\AppData\Local\{8F7A452B-E58E-4B17-9EE2-68B3FAB59969}
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]