31 Sty 2014, 21:23
31 Sty 2014, 21:55
:OTL
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=44444&tt=3612_2&babsrc=HP_ss&mntrId=cc4f8a4d000000000000d2f8daada56b
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=44444&tt=3612_2&babsrc=HP_ss&mntrId=cc4f8a4d000000000000d2f8daada56b
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idd/idd_1331926709_621261
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=119776&tt=3612_2&babsrc=HP_ss_din2g&mntrId=cc4f8a4d000000000000d2f8daada56b
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119776&tt=3612_2&babsrc=SP_ss&mntrId=cc4f8a4d000000000000d2f8daada56b
IE - HKU\S-1-5-21-2025089855-3785512668-198420323-1000\..\SearchScopes\{AB220020-A428-45CC-9958-C9532910C331}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=EB9A0FB7-A735-424E-8F82-BB26AEED6974&apn_sauid=D3095DD9-746B-47F5-B527-3612FDA49C51
[2013-12-29 17:17:29 | 000,002,575 | ---- | M] () -- C:\Users\Seven\AppData\Roaming\mozilla\firefox\profiles\p1hjcile.default-1352104840932\searchplugins\askcom.xml
[2013-04-28 19:56:11 | 000,006,523 | ---- | M] () -- C:\Users\Seven\AppData\Roaming\mozilla\firefox\profiles\p1hjcile.default-1352104840932\searchplugins\babylon.xml
[2013-02-26 14:32:27 | 000,001,294 | ---- | M] () -- C:\Users\Seven\AppData\Roaming\mozilla\firefox\profiles\p1hjcile.default-1352104840932\searchplugins\delta.xml
[2013-02-26 14:32:14 | 000,006,520 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-03-16 20:38:29 | 000,002,415 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml
[2013-12-21 11:38:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected]
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O4 - HKU\S-1-5-21-2025089855-3785512668-198420323-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Reg Error: Value error.)
[2014-01-31 18:53:04 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2025089855-3785512668-198420323-1000UA.job
[2014-01-31 10:10:22 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2025089855-3785512668-198420323-1000Core.job
[2012-09-08 10:05:02 | 000,000,000 | ---D | M] -- C:\Users\Seven\AppData\Roaming\Babylon
[2013-02-12 16:36:19 | 000,000,000 | ---D | M] -- C:\Users\Seven\AppData\Roaming\pdfforge
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=-
"AdobeCS6ServiceManager"=-
:Commands
[clearallrestorepoints]
[emptytemp]
01 Lut 2014, 00:16
01 Lut 2014, 14:15
rdpclip
AdobeAAMUpdater-1.0
Adobe ARM
SunJavaUpdateSched
Microsoft Windows
Internet Explorer
Microsoft Windows
\FacebookUpdateTaskUserS-1-5-21-2025089855-3785512668-198420323-1000Core
\FacebookUpdateTaskUserS-1-5-21-2025089855-3785512668-198420323-1000UA
\Hewlett-Packard\HP Support Assistant\PC Health Analysis
\Hewlett-Packard\HP Support Assistant\PC Tuneup
\Microsoft\Windows Defender\MP Scheduled Scan
\Microsoft\Windows Defender\MpIdleTask
\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
\Microsoft\Windows\NetTrace\GatherNetworkInfo
\Microsoft\Windows\Windows Media Sharing\UpdateLibrary
\MirageAgent
\{159DB42A-9910-44DA-816D-2F36F84BF9AE}
\{88A0CCD7-9B80-4020-91A7-9601CA47924C}
odserv
ose
WinDefend
WMPNetworkSvc
Java(TM) 6 Update 33
Java 7 Update 21
02 Lut 2014, 17:52
02 Lut 2014, 18:33
03 Lut 2014, 01:11
03 Lut 2014, 01:17
03 Lut 2014, 15:28
03 Lut 2014, 21:13
03 Lut 2014, 22:05
04 Lut 2014, 00:28
04 Lut 2014, 22:11