:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54
IE - HKU\S-1-5-21-2111757141-1368586507-1265563019-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=15425
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"
FF - prefs.js..browser.search.order.1: "Web Search"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"
FF - prefs.js..browser.search.order.1: "Web Search"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"
FF - prefs.js..browser.search.order.1: "Web Search"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"# Mozilla User Preferences
FF - prefs.js..browser.startup.homepage: "http://startsear.ch/?aff=2&cf=95a2a98e-1d0b-11e1-9bb3-a5c88e080e54"
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=736148&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=736148&ilc=12"
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2011-11-13 23:15:02 | 000,000,000 | ---D | M] (FYTDL DB Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\zaqxu74p.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
[2011-10-30 21:12:58 | 000,000,000 | ---D | M] (IncrediMail MediaBar 4 Community Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\zaqxu74p.default\extensions\{90eee664-34b1-422a-a782-779af65cdf6d}
[2011-10-12 17:27:46 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\zaqxu74p.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2010-12-31 14:40:49 | 000,000,000 | ---D | M] (MyAshampoo Toolbar) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\zaqxu74p.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2011-10-30 21:12:57 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\zaqxu74p.default\extensions\
[email protected] [2010-02-04 16:45:40 | 000,002,254 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\askcom.xml
[2010-01-20 12:19:10 | 000,000,923 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\conduit.xml
[2011-10-30 21:10:32 | 000,002,207 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\MyStart Search.xml
[2011-10-12 17:27:42 | 000,002,520 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\SearchResults.xml
[2011-07-11 19:04:02 | 000,000,633 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\startsear.xml
[2011-10-14 12:42:17 | 000,003,915 | ---- | M] () -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\zaqxu74p.default\searchplugins\SweetIM Search.xml
[2011-10-12 17:15:23 | 000,000,000 | ---D | M] (eBay-Toolbar by AB-Tools.com) -- C:\Program Files (x86)\mozilla firefox\extensions\
[email protected] [2011-10-12 17:27:42 | 000,002,520 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-2111757141-1368586507-1265563019-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O8:
64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O20:
64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\datamngr.dll (Bandoo Media, inc)
O20:
64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll) - C:\PROGRA~2\SEARCH~1\SEARCH~1\IEBHO.dll (Bandoo Media, inc)
[2012-02-18 16:36:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2111757141-1368586507-1265563019-1000UA.job
[2012-02-17 22:36:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2111757141-1368586507-1265563019-1000Core.job
:Commands
[emptytemp]