:OTL
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\Windows\system32\WinDir\Svchost.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-741995698-27301881-3234769972-1001..\Run: [HKCU] C:\Windows\SysWOW64\WinDir\Svchost.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-741995698-27301881-3234769972-1001..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKLM..\Run: [HDD Regenerator] "C:\Program Files (x86)\HDD Regenerator\HDD Regenerator.exe" File not found
O4 - HKLM..\Run: [HKLM] C:\Windows\SysWOW64\WinDir\Svchost.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [RAMDef] C:\Program Files (x86)\RAM Def\ramdef.exe -tray File not found
O4 - HKLM..\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe" File not found
O4:
64bit: - HKLM..\Run: [RpcEpMap] C:\Users\Johnny\AppData\Local\Microsoft\Windows\3096\RpcEpMap.exe ()
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
IE - HKU\S-1-5-21-741995698-27301881-3234769972-1001\..\SearchScopes\{ECA735D2-4A50-4C4E-A692-078D6EE48301}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&locale=en_US&apn_ptnrs=2K&apn_dtid=YYYYYYYYPL&apn_uid=C879F88D-81C7-47E2-8D6F-05316B9CEA14&apn_sauid=CC5FAC37-D361-4712-985F-A2541EB54D37
O7 - HKU\S-1-5-21-741995698-27301881-3234769972-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\Windows\system32\WinDir\Svchost.exe (Microsoft Corporation)
:Files
C:\Users\Johnny\AppData\Roaming\hellomoto
C:\Users\Johnny\AppData\Local\Microsoft\Windows\3096
C:\Windows\SysWOW64\WinDir
C:\Windows\system32\WinDir
C:\Users\Johnny\AppData\Local\*.html
C:\Windows\Tasks\SidebarExecute.job
C:\Windows\Tasks\RunOW.job
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=-
"Start Page"="about:blank"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=-
"Start Page"="about:blank"
:Commands
[emptyflash]
[resethosts]
[emptytemp]