27 Gru 2012, 12:50
27 Gru 2012, 12:56
:OTL
SRV - [2012-12-27 10:12:16 | 000,225,280 | R--- | M] (Корпорация Майкрософт) [Auto | Stopped] -- C:\Users\Filip\wgsdgsdgdsgsd.dll -- (Winmgmt)
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=60e3e79e-2374-11e1-811b-00138fd02791&q={searchTerms}
IE - HKU\S-1-5-21-3914684262-3437924519-3361531721-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=60e3e79e-2374-11e1-811b-00138fd02791&q={searchTerms}
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=60e3e79e-2374-11e1-811b-00138fd02791&q="
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
[2012-10-02 19:23:29 | 000,000,792 | ---- | M] () -- C:\Users\Filip\AppData\Roaming\mozilla\firefox\profiles\kg99vxdc.default\searchplugins\startsear.xml
[2011-10-27 14:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2012-12-27 10:12:16 | 000,225,280 | R--- | C] (Корпорация Майкрософт) -- C:\Users\Filip\wgsdgsdgdsgsd.dll
[2012-12-27 10:28:36 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012-12-27 10:52:22 | 000,001,056 | ---- | M] () -- C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2012-12-27 10:12:57 | 000,002,890 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.js
:Commands
[clearallrestorepoints]
[emptytemp]
27 Gru 2012, 13:24
27 Gru 2012, 13:53
:OTL
[2012-12-27 10:12:57 | 000,001,056 | ---- | C] () -- C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
:Commands
[reboot]
27 Gru 2012, 14:23
27 Gru 2012, 14:27