07 Cze 2014, 21:24
07 Cze 2014, 23:04
07 Cze 2014, 23:32
08 Cze 2014, 10:42
08 Cze 2014, 13:12
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ewa\AppData\Local\Temp\catchme.sys -- (catchme)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=abnew1&chnl=abnew1&cd=2XzutAtN2Y1L1Qzu0DtD0D0Fzy0A0DyB0F0F0AzytCyCtD0CtN0D0TzutBtDtCtBtDyDtCyC&cr=100901830
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=abnew1&chnl=abnew1&cd=2XzutAtN2Y1L1Qzu0DtD0D0Fzy0A0DyB0F0F0AzytCyCtD0CtN0D0TzutBtDtCtBtDyDtCyC&cr=100901830
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2419}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=419&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=110819&tt=100512_2_&babsrc=HP_ss&mntrId=c69b160c000000000000d0df9ad7ffa9
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_8&idate=2014-04-22&ent=hp&u=D92D0DB3B7F3E674860D435356564171
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes,Backup.Old.DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes\{0BBC3CF9-03DC-531E-9708-03042AA794A6}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&tt=100512_2_&babsrc=SP_ss&mntrId=c69b160c000000000000d0df9ad7ffa9
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=abnew1&chnl=abnew1&cd=2XzutAtN2Y1L1Qzu0DtD0D0Fzy0A0DyB0F0F0AzytCyCtD0CtN0D0TzutBtDtCtBtDyDtCyC&cr=100901830
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=2014-04-22&hsimp=yhs-lavasoft&ent=ch&q={searchTerms}
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2419}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=419&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
[2013-08-18 18:46:41 | 000,002,273 | ---- | M] () -- C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\enxshct2.default\searchplugins\bingp.xml
[2012-05-16 19:23:16 | 000,002,305 | ---- | M] () -- C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\enxshct2.default\searchplugins\Search.xml
[2012-12-25 17:25:45 | 000,002,515 | ---- | M] () -- C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\enxshct2.default\searchplugins\Search_Results.xml
[2012-05-16 19:12:41 | 000,002,352 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012-12-25 17:25:45 | 000,002,515 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
O3 - HKU\S-1-5-21-1293819493-3548736052-2493902398-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
[2012-05-16 19:12:23 | 000,000,000 | ---D | M] -- C:\Users\Ewa\AppData\Roaming\Babylon
:Commands
[clearallrestorepoints]
[emptytemp]
08 Cze 2014, 14:24
08 Cze 2014, 21:47