:OTL
[2011-04-24 11:56:04 | 000,000,000 | ---D | M] -- C:\Users\Milena\AppData\Roaming\AVG10
[2013-02-17 11:46:22 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\spmonitor.job
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9:
64bit: - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found
O9:
64bit: - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html File not found
O8:
64bit: - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O4 - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\Media Finder.exe" /opentotray File not found
O4 - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKLM..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
O4 - HKLM..\Run: [] File not found
O4:
64bit: - HKLM..\Run: [AvMenu] C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe File not found
O3 - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files (x86)\free-downloads.net\prxtbfre0.dll File not found
O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\prxtbfre0.dll File not found
O3 - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
[2013-01-15 13:41:38 | 000,003,269 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml
[2013-02-16 09:15:53 | 000,000,000 | ---D | M] (ArcaBit Ext.) -- C:\Program Files (x86)\mozilla firefox\extensions\
[email protected][2013-02-17 00:11:26 | 000,002,323 | ---- | M] () -- C:\Users\Milena\AppData\Roaming\mozilla\firefox\profiles\scor1xfn.default\searchplugins\askcom.xml
[2010-01-20 11:16:28 | 000,000,939 | ---- | M] () -- C:\Users\Milena\AppData\Roaming\mozilla\firefox\profiles\scor1xfn.default\searchplugins\conduit.xml
[2012-11-19 16:54:56 | 000,002,060 | ---- | M] () -- C:\Users\Milena\AppData\Roaming\mozilla\firefox\profiles\scor1xfn.default\searchplugins\softonic.xml
[2013-01-15 13:41:38 | 000,003,269 | ---- | M] () -- C:\Users\Milena\AppData\Roaming\mozilla\firefox\profiles\scor1xfn.default\searchplugins\Web Search.xml
[2013-02-17 00:11:26 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Milena\AppData\Roaming\mozilla\Firefox\Profiles\scor1xfn.default\extensions\
[email protected][2012-11-19 16:55:02 | 000,000,000 | ---D | M] (softonic.com) -- C:\Users\Milena\AppData\Roaming\mozilla\Firefox\Profiles\scor1xfn.default\extensions\
[email protected][2013-01-15 13:41:50 | 000,000,000 | ---D | M] (Certified Toolbar) -- C:\Users\Milena\AppData\Roaming\mozilla\Firefox\Profiles\scor1xfn.default\extensions\{624ad42d-e714-46b4-843e-c7094f740b0f}
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.certified-toolbar.com?si=33953&home=true&tid=2958"
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\SearchScopes\{6C44AA50-304A-498D-9060-E6F80668319E}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms}
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.softonic.com/INF00040/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=667
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\SearchScopes\{474C4320-B7BB-401D-A061-7C6861183BCE}: "URL" = http://search.avg.com/route/?d=4db4002a&v=6.103.18.1&i=23&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=BT5&o=15443&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=GX&apn_dtid=YYYYYYB3PL&apn_uid=4AEEC884-C4DA-4F9A-807F-224909B4AD82&apn_sauid=ADDE6CCD-6133-4532-9041-472482511A2A
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - SOFTWARE\Classes\CLSID\{ecdee021-0d17-467f-a1ff-c7a115230949}\InprocServer32 File not found
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKU\S-1-5-21-2439142372-3573659850-1218223454-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - SOFTWARE\Classes\CLSID\{ecdee021-0d17-467f-a1ff-c7a115230949}\InprocServer32 File not found
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q=
:Files
C:\Users\Milena\AppData\Local\Temp*.html
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=-
"UpdateLBPShortCut"=-
"UpdateP2GoShortCut"=-
:Commands
[emptytemp]