11 Sty 2013, 18:26
12 Sty 2013, 12:53
14 Sty 2013, 13:57
14 Sty 2013, 20:14
15 Sty 2013, 01:44
15 Sty 2013, 18:01
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=21d0ffa0-2cea-11e1-beb8-0021866bb104
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157
IE - HKLM\..\SearchScopes\{D4F9C292-8DBC-4C8C-AC9F-2DC7D62E4FDF}: \"URL\" = http://startsear.ch/?aff=2&src=sp&cf=21d0ffa0-2cea-11e1-beb8-0021866bb104&q={searchTerms}
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=21d0ffa0-2cea-11e1-beb8-0021866bb104
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No CLSID value found
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: \"URL\" = http://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101067&mntrId=66fd6f770000000000000015833da499
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: \"URL\" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157
IE - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\SearchScopes\{D8CC68F4-B022-4863-8882-52AA2B883398}: \"URL\" = http://startsear.ch/?aff=2&src=sp&cf=21d0ffa0-2cea-11e1-beb8-0021866bb104&q={searchTerms}
FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: f:\gry\Ganymede\Plugins\npganymedenet.dll File not found
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000..\Run: [] File not found
O4 - HKU\.DEFAULT..\RunOnce: [] File not found
O4 - HKU\S-1-5-18..\RunOnce: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [] File not found
O4 - HKU\S-1-5-20..\RunOnce: [] File not found
O4 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000..\Run: [WINSXS32] C:\Users\hp\AppData\Roaming\97D7.exe File not found
O4 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000..\Run: [Zjtytx] C:\Users\hp\AppData\Roaming\Zjtytx.exe File not found
O4 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000..\Run: [] File not found
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
[2013-01-11 14:14:19 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2755236839-2705045316-3623858159-1000UA.job
:Files
C:\Users\hp\AppData\Local\Temp*.html
:Reg
[HKEY_USERS\S-1-5-21-2755236839-2705045316-3623858159-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[clearallrestorepoints]
[emptytemp]
16 Sty 2013, 00:44
18 Sty 2013, 17:41
:OTL
[2012-09-02 09:31:35 | 000,033,377 | ---- | C] () -- C:\Users\hp\AppData\Roaming\6A08.exe
[2012-08-29 09:07:51 | 000,033,233 | ---- | C] () -- C:\Users\hp\AppData\Roaming\BDF1.exe
[2012-03-26 20:51:30 | 000,000,132 | ---- | C] () -- C:\Users\hp\AppData\Local\BronNetDomList.bat
[2012-03-26 20:39:53 | 000,012,393 | ---- | C] () -- C:\Users\hp\AppData\Local\Update.12.Bron.Tok.bin
[2013-01-15 17:14:00 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2755236839-2705045316-3623858159-1000Core.job
O4 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000..\Run: [Akamai NetSession Interface] "C:\Users\hp\AppData\Local\Akamai\netsession_win.exe" File not found
O3 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-2755236839-2705045316-3623858159-1000\..\Toolbar\WebBrowser: (no name) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No CLSID value found.
19 Sty 2013, 10:40
19 Sty 2013, 17:32
23 Sty 2013, 16:07
23 Sty 2013, 17:21
25 Sty 2013, 12:17
25 Sty 2013, 12:23
25 Sty 2013, 20:53