:OTL
IE - HKU\S-1-5-21-39138238-2105388083-3416316383-1000\..\SearchScopes\{C8262E91-8C0E-4EFE-A122-01E445421B1F}: "URL" =
http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
CHR - homepage:
http://start.iminent.com/?appId=546C546 ... C465298EECCHR - Extension: MegaSkipper = C:\Users\hsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.66_0\
[2013/05/09 02:03:00 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-39138238-2105388083-3416316383-1000UA.job
[2013/05/08 21:16:08 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2013/05/08 11:03:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-39138238-2105388083-3416316383-1000Core.job
@Alternate Data Stream - 190 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:EE198B1F
@Alternate Data Stream - 179 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:8AE92FD3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:B6E6C4EA
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:4FA837B4
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:2652902F
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E5B07840
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:587F3582
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:4C3D5A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:D999FFD5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F6A0889A
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:943971F5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E0888117
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:B6D84F71
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:E5496666
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E8C44CB4
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:BEE39E9B
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3651A580
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A5241382
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:ECF3C50F
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:8075370B
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:28BEC2EC
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2C86E2AD
:Commands
[emptytemp]
[createrestorepoint]