01 Kwi 2014, 00:26
01 Kwi 2014, 14:31
:OTL
SRV:64bit: - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe -- (McComponentHostService)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158
IE - HKU\S-1-5-21-2175261183-2476409623-1182026083-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2412158
IE - HKU\S-1-5-21-2175261183-2476409623-1182026083-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2412158
IE - HKU\S-1-5-21-2175261183-2476409623-1182026083-1000\..\SearchScopes\{E5EA0DEF-6123-4AE2-8177-7189A4D1E1DC}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^PL&apn_uid=56F8087D-AAD9-4089-ACB5-E3A229B7E5FF&apn_sauid=BA89B304-A4AA-44B8-B2E5-ED746FD1E35B
FF - prefs.js..browser.search.defaultthis.engineName: "RealoreStudios Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2412158&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com Search"
[2012-09-01 22:23:52 | 000,002,299 | ---- | M] () -- C:\Users\Arlet\AppData\Roaming\mozilla\firefox\profiles\3hs3qrw3.default\searchplugins\askcom.xml
[2013-06-20 08:34:45 | 000,002,306 | ---- | M] () -- C:\Users\Arlet\AppData\Roaming\mozilla\firefox\profiles\3hs3qrw3.default\searchplugins\askcomsearch.xml
[2012-05-30 12:48:44 | 000,000,931 | ---- | M] () -- C:\Users\Arlet\AppData\Roaming\mozilla\firefox\profiles\3hs3qrw3.default\searchplugins\conduit.xml
[2013-12-15 20:11:29 | 000,000,000 | ---D | M] (RealoreStudios) -- C:\Users\Arlet\AppData\Roaming\mozilla\Firefox\Profiles\3hs3qrw3.default\extensions\{03fee850-0101-4e9e-b6d4-6fc74d3db360}
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-2175261183-2476409623-1182026083-1000..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Arlet\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Arlet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
[2014-03-31 22:19:18 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2175261183-2476409623-1182026083-1000Core.job
[2014-03-31 22:18:00 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2175261183-2476409623-1182026083-1000UA.job
:Commands
[clearallrestorepoints]
[emptytemp]
01 Kwi 2014, 22:59
01 Kwi 2014, 23:02
01 Kwi 2014, 23:15
01 Kwi 2014, 23:23
:OTL
O3 - HKU\S-1-5-21-2175261183-2476409623-1182026083-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll File not found