:OTL
PRC - C:\Documents and Settings\Administrateur\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe ()
MOD - C:\Documents and Settings\Administrateur\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe ()
MOD - C:\WINDOWS\system32\LXF3PMRC.DLL ()
MOD - C:\WINDOWS\system32\LXF3PMON.DLL ()
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.com/?crg=4.0003002IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: %µ£URL%µ£ =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.com/?crg=4.0003002IE - HKCU\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: %µ£URL%µ£ =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: %µ£URL%µ£ =
http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=989ee75d0000000000000023c3e23abc&tlver=1.4.19.19&ss=1&affID=18026
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: %µ£URL%µ£ =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1394623
FF - prefs.js..browser.search.defaultenginename: %µ£SweetIM Search%µ£
FF - prefs.js..browser.startup.homepage: %µ£http://home.sweetim.com/?crg=4.0003002%µ£
FF - prefs.js..keyword.URL: %µ£http://search.conduit.com/ResultsExt.aspx?ctid=CT1394623&q=%µ£
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: %µ£http://search.babylon.com/?babsrc=SP_ss&mntrId=989ee75d0000000000000023c3e23abc&tlver=1.4.19.19&instlRef=sst&ss=1&affID=18026&q=%µ£
[2011/10/16 22:58:48 | 000,000,000 | ---D | M] (PriceGong) -- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\ytsh9f7e.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (OfferBox) - {703740c1-0f1a-4cec-a4df-d78db0158477} - C:\Program Files\OfferBox\extensions-4.0.4498.53\offerbox_air_iexplorer.dll (Aedge Performance BCN SL)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKCU..\Run: [Mattel HWRC Launcher] C:\Documents and Settings\Administrateur\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe ()
MsConfig - StartUpReg:
BabylonToolbar - hkey= - key= - File not found
[2011/09/11 18:22:14 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXF3FXPU.DLL
[2011/09/11 18:22:14 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\LXF3PMRC.DLL
[2011/01/29 17:00:22 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011/01/22 23:39:16 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/01/22 23:32:33 | 000,001,984 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/01 15:35:00 | 000,003,584 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
[2011/11/10 23:41:16 | 000,010,752 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon8255BBAC1.exe
[2011/11/10 23:41:20 | 000,006,144 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F734.exe
[2011/11/10 23:41:20 | 000,015,360 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F738.exe
[2011/01/15 13:49:22 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{BA2F3EBC-FE07-4AB5-B906-14DF2C74C523}\_2CD174B33184278049EBEB.exe
[2011/01/15 13:49:22 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{BA2F3EBC-FE07-4AB5-B906-14DF2C74C523}\_BFC829F8AF526E9E67848C.exe
[2012/07/04 11:27:17 | 000,027,411 | ---- | M] () -- C:\Documents and Settings\Administrateur\Local Settings\Temp\i4jdel0.exe
[2012/07/02 17:45:03 | 000,049,075 | ---- | M] () -- C:\Documents and Settings\Administrateur\Local Settings\Temp\uninstall.exe
[2012/07/06 01:06:14 | 000,000,000 | R--- | M] () -- C:\Documents and Settings\Administrateur\Local Settings\Temp\kbdtuf.dll
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
:Files
C:\Documents and Settings\Administrateur\Local Settings\Application Data\sswat_hwrc_win_live\mattelhwrc_launcher.exe
:commands
[emptytemp]
[emptyflash]
[resethosts]