:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
Dostępne tylko dla zarejestrowanych użytkowników IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkowników IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&babsrc=SP_def_din2g&affID=121562
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes\{41BCEEF5-8EAF-4797-BAE7-38B776101040}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes\{69ABAE4C-47BC-4EAD-A2B3-ED08ED617830}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&SearchSource=4&ctid=ct3135048
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&rlz=1I7GGLD_pl&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Robert\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
O4 - HKLM..\Run: [Onet.pl AutoUpdate] "C:\Program Files (x86)\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexe File not found
O4 - HKU\S-1-5-21-3417662356-3401972834-3553740316-1000..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel -
res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Wyślij &do programu OneNote -
res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
[2013-09-03 10:26:34 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
[2013-09-03 10:26:33 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\FilesFrog Update Checker
[2013-04-18 07:08:02 | 001,174,028 | ---- | C] () -- C:\Windows\SysWow64\sig.bin
[2013-04-08 01:19:40 | 000,024,150 | ---- | C] () -- C:\Users\Robert\.TransferManager.db
[2013-01-15 13:10:06 | 000,000,001 | ---- | C] () -- C:\Users\Robert\AppData\Local\llftool.4.25.agreement
[2012-10-28 15:50:51 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\jEdit
[2012-09-09 10:25:48 | 000,000,000 | ---D | M] -- C:\Users\k\AppData\Roaming\Opera
[2012-12-26 21:21:05 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\AutoUpdate
[2013-09-03 10:28:47 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\BabSolution
[2013-04-07 12:33:16 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\Babylon
[2013-04-07 12:33:41 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\Delta
[2012-09-25 20:18:40 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\IrfanView
[2012-11-02 00:17:11 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\NapiProjekt
[2013-04-07 12:32:54 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\OpenCandy
[2012-09-07 14:01:28 | 000,000,000 | ---D | M] -- C:\Users\Robert\AppData\Roaming\Opera
:Services
gupdate
gupdatem
:Files
C:\Program Files (x86)\Google\Update
C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]