05 Wrz 2014, 13:44
05 Wrz 2014, 14:02
:OTL
DRV:64bit: - [2014-04-24 12:35:28 | 000,061,120 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\{572f484b-455f-44b0-9d6a-da3ad2071365}Gw64.sys -- ({572f484b-455f-44b0-9d6a-da3ad2071365}Gw64)
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.aartemis.com/web/?type=ds&ts=1387822513&from=cor&uid=_&q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&ptr=100&q={searchTerms}&crg=3.1010006.10029&barid={8CBA789A-E17B-11E2-87DF-0022158DA533}
E - HKU\S-1-5-21-3743841706-3235595561-791980290-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=88070022158DA533&affID=123627&tt=250613_gr4&tsp=4929
IE - HKU\S-1-5-21-3743841706-3235595561-791980290-1001\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={8CBA789A-E17B-11E2-87DF-0022158DA533}&crg=3.1010006.10029&st=23&ptr=100
IE - HKU\S-1-5-21-3743841706-3235595561-791980290-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 218.28.49.172:3128
O3 - HKU\S-1-5-21-3743841706-3235595561-791980290-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
:Commands
[clearallrestorepoints]
[emptytemp]
05 Wrz 2014, 15:22
05 Wrz 2014, 18:18
:OTL
[2013-12-23 20:16:05 | 000,000,000 | ---D | M] -- C:\Users\Adam Ma_\AppData\Roaming\newnext.me
[2013-12-23 20:29:25 | 000,000,000 | ---D | M] -- C:\Users\Adam Ma_\AppData\Roaming\aartemis
05 Wrz 2014, 22:09
06 Wrz 2014, 14:27
10 Wrz 2014, 23:10