:otl
PRC - [2014/06/15 16:53:18 | 000,317,720 | ---- | M] () -- C:\Program Files (x86)\webget\updatewebget.exe
PRC - [2014/06/15 16:48:54 | 000,317,720 | ---- | M] () -- C:\Program Files (x86)\webget\bin\utilwebget.exe
PRC - [2014/06/15 07:44:02 | 000,096,536 | ---- | M] () -- C:\Program Files (x86)\webget\bin\webget.BrowserAdapter.exe
PRC - [2014/04/27 19:01:49 | 002,557,976 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2014/04/27 19:01:49 | 001,801,240 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe
PRC - [2014/04/27 19:01:49 | 000,159,768 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\loggingserver.exe
PRC - [2014/03/11 23:36:06 | 000,247,968 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
MOD - [2014/06/15 07:44:02 | 000,096,536 | ---- | M] () -- C:\Program Files (x86)\webget\bin\webget.BrowserAdapter.exe
MOD - [2014/06/15 07:44:01 | 000,183,576 | ---- | M] () -- C:\Program Files (x86)\webget\bin\webgetBAApp.dll
MOD - [2014/04/27 19:01:49 | 002,557,976 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2014/04/27 19:01:49 | 000,519,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\log4cplusU.dll
SRV - [2014/04/27 19:01:49 | 001,801,240 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe -- (vToolbarUpdater18.1.0)
SRV - [2014/06/15 16:53:18 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\webget\updatewebget.exe -- (Update webget)
SRV - [2014/06/15 16:48:54 | 000,317,720 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\webget\bin\utilwebget.exe -- (Util webget)
IE - HKU\S-1-5-21-2168072139-2892889087-111868694-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://speedial.com/?f=1&a=spd_tele_14_ ... 171566&ir=IE - HKU\S-1-5-21-2168072139-2892889087-111868694-1001\..\SearchScopes,DefaultScope = {31090377-0740-419E-BEFC-A56E50500D5B}
IE - HKU\S-1-5-21-2168072139-2892889087-111868694-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://www.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=1A9D6C71D934D1BC
IE - HKU\S-1-5-21-2168072139-2892889087-111868694-1001\..\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}: "URL" =
http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_tele_14_22_ch&cd=2XzuyEtN2Y1L1QzuyC0CyBtC0DzytAyE0DtC0B0C0EyBzzyBtN0D0Tzu0SzzyByBtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDtByDtBtDtCyCtAtGtByC0E0BtGyEzy0CzztG0FtA0B0FtGyEyB0Azy0B0A0AzytByB0Czz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCtDtDyC0AtD0AzztGtAzzzzzztGyD0DyEyBtG0DtCyBtAtGyBzzyE0F0AtBtC0E0E0CyEtA2Q&cr=1184171566&ir=
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=119370&babsrc=HP_ss_din2g&mntrId=1A9D6C71D934D1BC"
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.0\\npsitesafety.dll File not found
[2013/05/02 09:02:38 | 000,006,471 | ---- | M] () -- C:\Users\Alizée\AppData\Roaming\mozilla\firefox\profiles\77vpl4rf.default\searchplugins\babylon.xml
[2013/05/02 09:02:38 | 000,006,471 | ---- | M] () -- C:\Users\Alizée\AppData\Roaming\mozilla\firefox\profiles\77vpl4rf.default\searchplugins\BrowserProtect.xml
[2013/03/24 17:08:44 | 000,001,294 | ---- | M] () -- C:\Users\Alizée\AppData\Roaming\mozilla\firefox\profiles\77vpl4rf.default\searchplugins\delta.xml
[2013/03/07 17:31:03 | 000,001,609 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-france.xml
[2013/03/24 17:08:11 | 000,006,468 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2013/03/07 17:31:04 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
CHR - Extension: No name found = C:\Users\Alizée\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.3.0.49_0\
CHR - Extension: No name found = C:\Users\Alizée\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll (AVG Secure Search)
:files
C:\Program Files (x86)\webget
C:\Users\Alizée\AppData\Roaming\Speedial
C:\Program Files (x86)\Speedial
C:\Program Files (x86)\Speedial
C:\Users\Alizée\AppData\Roaming\Babylon
C:\Users\Alizée\AppData\Roaming\Speedial
C:\ProgramData\FullRemove.exe
C:\Users\Alizée\Local Settings\Temp\oi_{F6673CA1-F369-4A23-B4B1-FDCE32BF410B}.exe
C:\Users\Alizée\Local Settings\Temp\uninst1.exe
C:\Users\Alizée\Local Settings\Temp\AskSLib.dll
C:\Program Files (x86)\AVG Secure Search
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\Microsoft\BingBar
C:\Users\Alizée\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\Alizée\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
:reg
[HKLM\Software\Wow6432Node\Google\Chrome\Extensions \ndibdjnfmopecpmkdieinmbadjfpblof]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webget]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3365E735-48A6-4194-9988-CE59AC5AE503}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Speedial]
:commands
[EMPTYTEMP]
[PURITY]
[REBOOT]