:OTL DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\HSF_CNXT.sys – (winachsf) DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\UIUSys.sys – (UIUSys) DRV - File not found [Kernel | Auto | Stopped] – system32\DRIVERS\mdmxsdk.sys – (mdmxsdk) DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\HSFHWICH.sys – (HSFHWICH) DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\HSF_DPV.sys – (HSF_DPV) DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ar5211.sys – (AR5211) IE - HKU\S-1-5-21-1491950412-2009852829-4049741679-1034\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=111434 … 164117912c IE - HKU\S-1-5-21-1491950412-2009852829-4049741679-1034…\SearchScopes{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: “URL” = http://search.babylon.com/?q={searchTerms}&affID=111434&babsrc=SP_ss&mntrId=6048aee300000000000000164117912c [2012-05-02 11:13:35 | 000,002,313 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml O3 - HKLM…\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.) [2012-05-02 11:13:41 | 000,000,000 | —D | C] – C:\Program Files\BabylonToolbar [2012-05-02 11:13:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Frozen Lust\Ustawienia lokalne\Dane aplikacji\Babylon [2012-05-02 11:13:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Frozen Lust\Dane aplikacji\Babylon [2012-05-02 11:13:43 | 000,000,237 | ---- | M] () – C:\user.js [2012-04-08 15:09:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Dane aplikacji\OpenCandy [2012-03-11 17:05:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\SweetIM :Reg [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] “BootExecute”=hex(7):61,00,75,00,74,00,6f,00,63,00,68,00,65,00,63,00,6b,00,20,\ 00,61,00,75,00,74,00,6f,00,63,00,68,00,6b,00,20,00,2a,00,00,00,00,00 :Commands [emptytemp]