:OTL
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:
64bit: - HKLM\..\SearchScopes\{420EF844-F749-4AB0-8C55-4515669ED071}: %µ£URL%µ£ =
http://slirsredirect.search.aol.com/sli ... 156&query={searchTerms}&invocationType=tb50hpcndtie7-fr-fr
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{420EF844-F749-4AB0-8C55-4515669ED071}: %µ£URL%µ£ =
http://slirsredirect.search.aol.com/sli ... 156&query={searchTerms}&invocationType=tb50hpcndtie7-fr-fr
IE - HKU\S-1-5-21-1029564177-2171347870-3638830632-1001\..\SearchScopes,DefaultScope = {FE0C2CED-3D6E-4112-8078-3FC7BD7A4AA5}
[2012/02/08 13:42:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
O3:
64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1029564177-2171347870-3638830632-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:
64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
[2012/06/18 17:25:42 | 000,022,016 | ---- | C] () -- C:\Windows\Installer\{0933efbf-ea2d-9e6a-9b99-b419583b72d2}\U\800000cb.@
[2012/06/18 17:25:41 | 000,016,896 | ---- | C] () -- C:\Windows\Installer\{0933efbf-ea2d-9e6a-9b99-b419583b72d2}\U\80000000.@
[2012/01/11 19:19:52 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{0933efbf-ea2d-9e6a-9b99-b419583b72d2}\@
[2011/12/23 11:08:05 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
:files
C:\Windows\Installer\{0933efbf-ea2d-9e6a-9b99-b419583b72d2}
C:\ProgramData\.zreglib
C:\Windows\SysWow64\bandoolmx.dll
:commands
[emptytemp]
[emptyflash]
[reboot]