:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: %µ£URL%µ£ =
http://feed.snap.do/?publisher=Download ... type=ds&q={searchTerms}
IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://feed.snap.do/?publisher=Download ... type=ds&q={searchTerms}
IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.delta-search.com/?affID=1193 ... fd2267df2/IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://feed.snap.do/?publisher=Download ... type=ds&q={searchTerms}
IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://feed.snap.do/?publisher=Download ... type=ds&q={searchTerms}
IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-556064579-2628993905-1687371099-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: %µ£URL%µ£ =
http://www.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=1434101300000000000000ffd2267df2
[2013/02/09 22:07:30 | 000,006,484 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013/03/09 13:09:26 | 000,000,000 | ---D | C] -- C:\Users\Romain.G\AppData\Local\{D43E8A0E-F98A-4E45-93CA-D5B8E999A7BC}
[2013/03/08 18:42:02 | 000,000,000 | ---D | C] -- C:\Users\Romain.G\AppData\Local\{4F264A2C-18FF-49D4-9B80-8332E736FB2D}
[2013/03/05 13:26:40 | 000,000,000 | ---D | C] -- C:\Users\Romain.G\AppData\Roaming\ZProDuCTioN
[2013/02/28 18:36:57 | 000,087,608 | ---- | C] () -- C:\Users\Romain.G\AppData\Roaming\inst.exe
[2012/03/28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013/02/09 22:07:12 | 000,000,000 | ---D | M] -- C:\Users\Romain.G\AppData\Roaming\Babylon
[2013/03/05 13:36:29 | 000,000,000 | ---D | M] -- C:\Users\Romain.G\AppData\Roaming\ZProDuCTioN
[2013/02/09 22:07:12 | 000,000,000 | ---D | M] -- C:\Users\Romain.G\AppData\Roaming\Babylon
[2012/12/31 13:26:37 | 000,028,862 | R--- | M] () -- C:\Users\Romain.G\AppData\Roaming\Microsoft\Installer\{3D55339F-D991-4806-9FD4-00B815714AF1}\_18be6784.exe
[2012/12/31 13:26:37 | 000,028,862 | R--- | M] () -- C:\Users\Romain.G\AppData\Roaming\Microsoft\Installer\{3D55339F-D991-4806-9FD4-00B815714AF1}\_294823.exe
[2012/02/19 18:46:21 | 000,010,134 | R--- | M] () -- C:\Users\Romain.G\AppData\Roaming\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
[2012/02/19 18:46:36 | 000,010,134 | R--- | M] () -- C:\Users\Romain.G\AppData\Roaming\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
:commands
[emptytemp]
[emptyflash]
[resethosts]