13 Kwi 2014, 11:03
13 Kwi 2014, 11:55
:OTL
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=19317&babsrc=SP_ss&mntrId=0e5b7e2f00000000000046ac4c32ca3d
IE - HKCU\..\SearchScopes\{205E4C6A-A463-49D0-BF98-7C64767C6659}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10267&src=crm&q={searchTerms}&locale=en_GB&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^GB&apn_uid=57179c67-2020-43e2-9680-28406a8a9593&apn_sauid=6BB70637-EC39-45D5-8ABC-FE5D7132CAB2
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "uTorrentControl_v2 Customized Web Search"
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.1.9
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3220468&SearchSource=2&CUI=UN16249284135108222&UM=&q="
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\oem\AppData\Roaming\Mozilla\Extensions\[email protected] [2013/02/22 15:15:39 | 000,000,000 | ---D | M]
[2013/12/17 14:31:25 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\oem\AppData\Roaming\mozilla\Firefox\Profiles\2ssx47jl.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2013/02/22 15:15:27 | 000,000,000 | ---D | M] (Smiley Bar for Facebook) -- C:\Users\oem\AppData\Roaming\mozilla\Extensions\statuswinks@StatusWinks
[2013/03/29 23:02:27 | 000,002,585 | ---- | M] () -- C:\Users\oem\AppData\Roaming\mozilla\firefox\profiles\2ssx47jl.default\searchplugins\askcom.xml
[2012/12/30 12:30:45 | 000,001,066 | ---- | M] () -- C:\Users\oem\AppData\Roaming\mozilla\firefox\profiles\2ssx47jl.default\searchplugins\utorrentcontrolv2-customized-web-search.xml
CHR - Extension: uTorrentControl_v2 = C:\Users\oem\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.29.0.520_0\
CHR - Extension: uTorrentControl_v2 = C:\Users\oem\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.29.0.520_0\nativeMessaging\nmHost
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - Startup: C:\Users\oem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uoto.bat ()
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
[2014/03/29 11:18:46 | 000,332,020 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\j68bn8z9bn.faa
[2014/03/29 11:17:43 | 000,332,020 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\uoto.faa
[2014/01/09 15:57:44 | 000,295,728 | ---- | C] (VuuPC Limited) -- C:\Users\oem\AppData\Local\VuuPCBaseSetup.exe
[2014/04/13 09:03:09 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
[2014/04/06 17:11:51 | 000,013,880 | ---- | M] () -- C:\ProgramData\7arj2vh.bbr
[2014/03/29 15:52:15 | 000,013,880 | ---- | M] () -- C:\ProgramData\j68bn8z9bn.bbr
[2014/04/06 17:11:51 | 000,013,880 | ---- | M] () -- C:\ProgramData\7arj2vh.bbr
:Commands
[clearallrestorepoints]
[emptytemp]