:OTL
SRV - File not found [Auto | Running] -- C:\Program Files\Yontoo\Y2Desktop.Updater.exe C:\Users\ARO\AppData\Roaming\Yontoo\YontooDesktop.exe -- (Yontoo Desktop Updater)
DRV - File not found [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VBoxNetFlt.sys -- (VBoxNetFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\ute3njk5.sys -- (ute3njk5)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\FXDrv32.sys -- (FXDrv32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\ARO\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\AsrCDDrv.sys -- (AsrCDDrv)
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=f542ce29-1536-426e-adda-f629c8bd8f23&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={2C28A2DA-C9B9-11E1-981C-0025227787CD}
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=114874&tt=120912_pcp_3912_7&babsrc=HP_ss&mntrId=d415498400000000000000ff5fa0abf7
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=f542ce29-1536-426e-adda-f629c8bd8f23&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=f542ce29-1536-426e-adda-f629c8bd8f23&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=f542ce29-1536-426e-adda-f629c8bd8f23&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=114874&tt=120912_pcp_3912_7&babsrc=SP_ss&mntrId=d415498400000000000000ff5fa0abf7
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\..\SearchScopes\{ED0C05BA-956F-4883-AEB9-2B52A8F422B0}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={2C28A2DA-C9B9-11E1-981C-0025227787CD}
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=114874&tt=120912_pcp_3912_7&babsrc=HP_ss&mntrId=d415498400000000000000ff5fa0abf7"
FF - prefs.js..extensions.enabledAddons: plugin%40yontoo.com:1.20.02
[2013-04-20 19:49:16 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\ARO\AppData\Roaming\mozilla\Firefox\Profiles\yz1hfydm.default\extensions\
[email protected] \extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012-09-25 15:44:21 | 000,002,223 | ---- | M] () -- C:\Users\ARO\AppData\Roaming\mozilla\firefox\profiles\yz1hfydm.default\searchplugins\BabylonMngr.xml
[2012-07-24 13:49:33 | 000,004,113 | ---- | M] () -- C:\Users\ARO\AppData\Roaming\mozilla\firefox\profiles\yz1hfydm.default\searchplugins\sweetim.xml
[2012-06-02 18:46:17 | 000,002,474 | ---- | M] () -- C:\Users\ARO\AppData\Roaming\mozilla\firefox\profiles\yz1hfydm.default\searchplugins\Web Search.xml
[2012-09-25 15:44:39 | 000,002,360 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012-07-20 21:01:13 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files\Mozilla Firefox\extensions\
[email protected] CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\ARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.11.21.5_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\ARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.11.21.5_0\plugins/np-cwmp.dll
CHR - Extension: Yontoo = C:\Users\ARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_0\
CHR - Extension: Yontoo = C:\Users\ARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.3_0\
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKU\S-1-5-21-2074215493-1182119007-4286318891-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : IE HTTPAnalyzer V6 - {0EE59015-EBDF-4986-8F80-DB00975ABDCD} - Reg Error: Value error. File not found
[2013-04-24 17:30:19 | 000,009,001 | ---- | M] () -- C:\gg0.html
:Commands
[clearallrestorepoints]
[emptytemp]