29 Gru 2012, 21:52
29 Gru 2012, 22:39
30 Gru 2012, 00:53
30 Gru 2012, 01:10
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtB0CtBzytBtB0ByBtD0BtN0D0Tzu0CtAtAzztN1L2XzutBtFtBtFtDtFtAyEyE&cr=395708750
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtB0CtBzytBtB0ByBtD0BtN0D0Tzu0CtAtAzztN1L2XzutBtFtBtFtDtFtAyEyE&cr=395708750
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtB0CtBzytBtB0ByBtD0BtN0D0Tzu0CtAtAzztN1L2XzutBtFtBtFtDtFtAyEyE&cr=395708750
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtB0CtBzytBtB0ByBtD0BtN0D0Tzu0CtAtAzztN1L2XzutBtFtBtFtDtFtAyEyE&cr=395708750
IE - HKU\S-1-5-21-1771593470-3012635902-189330645-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtB0CtBzytBtB0ByBtD0BtN0D0Tzu0CtAtAzztN1L2XzutBtFtBtFtDtFtAyEyE&cr=395708750
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1771593470-3012635902-189330645-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKU\S-1-5-21-1771593470-3012635902-189330645-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Reg Error: Value error.)
[2012-12-03 18:27:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012-12-03 18:26:56 | 000,000,000 | ---D | C] -- C:\Users\Paulina\AppData\Local\Conduit
[2012-12-29 12:36:07 | 000,002,939 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2012-12-29 12:36:07 | 000,001,049 | ---- | M] () -- C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
:Files
C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
:Commands
[clearallrestorepoints]
[emptytemp]
30 Gru 2012, 09:48
30 Gru 2012, 10:12
30 Gru 2012, 10:20
30 Gru 2012, 10:22
30 Gru 2012, 10:29
30 Gru 2012, 12:28
30 Gru 2012, 13:08
30 Gru 2012, 13:28
30 Gru 2012, 13:42