03 Mar 2014, 22:27
04 Mar 2014, 00:00
:OTL
IE - HKU\S-1-5-21-1115324672-683725379-276214280-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&CUI=UN36010289410092480&UM=2&ctid=CT3288691
IE - HKU\S-1-5-21-1115324672-683725379-276214280-1000\..\SearchScopes\{37AA7277-1EB8-4135-B20F-35C080751B10}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3288691&CUI=UN36010289410092480&UM=2
IE - HKU\S-1-5-21-1115324672-683725379-276214280-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=12&q={searchTerms}&barid={87FD0310-BDBC-4EE8-A5C3-B4ED087495DD}
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN88568592810994138&UM=2&UP=SP0E4827BE-D76B-4C0F-87A7-67B213D6BB1E&SSPV="
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0
[2014-02-17 16:15:00 | 000,000,000 | ---D | M] (DivX Browser Bar) -- C:\Users\Magda\AppData\Roaming\mozilla\Firefox\Profiles\aeb16ai3.default\extensions\{77e8143b-6759-416e-b521-82cfed75150b}
[2012-11-03 18:58:55 | 000,004,002 | ---- | M] () -- C:\Users\Magda\AppData\Roaming\mozilla\firefox\profiles\aeb16ai3.default\searchplugins\sweetim.xml
[2013-01-09 23:52:45 | 000,000,000 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
CHR - Extension: DivX Browser Bar = C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho\10.26.9.505_0\
CHR - Extension: DivX Browser Bar = C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho\10.26.9.505_0\nativeMessaging\nmHost
CHR - Extension: AVG Security Toolbar = C:\Users\Magda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\18.0.0.248_0\
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe File not found
[2014-02-17 16:22:52 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2014-02-17 16:20:33 | 000,000,000 | ---D | C] -- C:\Users\Magda\AppData\Local\Conduit
[2014-02-17 16:19:43 | 000,000,000 | ---D | C] -- C:\Users\Magda\AppData\Local\CRE
[2014-02-17 16:18:41 | 000,000,000 | ---D | C] -- C:\Users\Magda\AppData\Local\SearchProtect
[2014-02-17 16:12:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Conduit
[2014-03-03 20:11:29 | 000,000,350 | ---- | M] () -- C:\windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
[2014-03-03 20:11:28 | 000,000,350 | ---- | M] () -- C:\windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXMediaServer"=-
:Commands
[clearallrestorepoints]
[emptytemp]
04 Mar 2014, 14:00
04 Mar 2014, 14:28
:OTL
O4 - HKU\S-1-5-21-1115324672-683725379-276214280-1000..\Run: [APISupport] "C:\windows\system32\Rundll32.exe" "C:\Users\Magda\AppData\Local\Conduit\APISupport\APISupport.dll",DLLRunAPISupport File not found
04 Mar 2014, 15:27
04 Mar 2014, 23:39
04 Mar 2014, 23:52
04 Mar 2014, 23:56
05 Mar 2014, 00:40
05 Mar 2014, 00:45
06 Mar 2014, 01:05
06 Mar 2014, 10:57
rdpclip
Adobe ARM
RTHDVCPL
Microsoft Windows
\AVG-Secure-Search-Update_JUNE2013_HP_rmv
\AVG-Secure-Search-Update_JUNE2013_TB_rmv
\BackgroundContainer Startup Task
\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
\Microsoft\Windows\NetTrace\GatherNetworkInfo
\Microsoft\Windows\Windows Media Sharing\UpdateLibrary
ose
osppsvc
WinDefend
WMPNetworkSvc
06 Mar 2014, 12:14
06 Mar 2014, 12:18