:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (IpInIp)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=vsl&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&affID=1101316&mntrId=6e30a2ad00000000000000242b88cbf3
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=vsl&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=1101316&mntrId=6e30a2ad00000000000000242b88cbf3
IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=JGCYO2xdLb-OYZ9hvN2Tz-Qezbc?q={searchTerms}
[2011-12-27 19:51:01 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\fmp59353.default\extensions\
[email protected][2011-12-27 19:23:50 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\Acer\AppData\Roaming\mozilla\Firefox\Profiles\fmp59353.default\extensions\
[email protected] [2011-12-27 19:24:25 | 000,002,289 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011-12-27 19:23:52 | 000,002,046 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
O4 - HKCU..\Run: [{758F5A74-6BBC-7EA3-B272-5CCC9CA6529C}] C:\Users\Acer\AppData\Roaming\Goky\axtyi.exe (Copyright (C) 2010-2011 Marvell Semiconductor)
[2012-03-04 14:45:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
[2012-03-04 17:37:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2048989084-971008106-2501131680-1000UA.job
[2012-03-04 17:31:00 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-03-04 10:38:27 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-03-03 23:37:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2048989084-971008106-2501131680-1000Core.job
:Files
C:\Program Files\RelevantKnowledge
C:\Users\Acer\AppData\Roaming\Goky
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"=-
"EgisTecLiveUpdate"=-
"NvMediaCenter"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Antivirus Protection 2012"=-
:Commands
[clearallrestorepoints]
[emptytemp]