HKLM-x32\...\Run: [] => [X] Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1755371218-3412237994-1746218496-1000\...\MountPoints2: {6c4e0517-4ea1-11e3-8ffc-74d02b96086c} - H:\LaunchU3.exe -a HKU\S-1-5-21-1755371218-3412237994-1746218496-1000\...\MountPoints2: {d6896687-cb1f-11e3-a1c7-74d02b96086c} - H:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.A14B04 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B} FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File CHR HomePage: Default -> hxxp://www.mystartsearch.com/?type=hp&ts=1417868158&from=amt&uid=SamsungXSSDX840XPROXSeries_S1ATNSAD757180A U3 a7ov7v0i; C:\Windows\System32\Drivers\a7ov7v0i.sys [0 ] (Microsoft Corporation) C:\Windows\System32\Drivers\a7ov7v0i.sys 2014-12-06 13:16 - 2014-12-06 13:27 - 00000000 ____D () C:\Users\Martin\AppData\Local\9793 C:\Users\Martin\AppData\Local\Temp\ammemb.dll C:\Users\Martin\AppData\Local\Temp\ammemb64.dll C:\Users\Martin\AppData\Local\Temp\Quarantine.exe C:\Users\Martin\AppData\Local\Temp\sqlite3.dll EmptyTemp: