:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkowników IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&pid=512&r=2013/07/09&hid=2209213141&lg=EN&cc=PL&unqvl=24
IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
Dostępne tylko dla zarejestrowanych użytkowników IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Before =
IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&babsrc=SP_ss&mntrId=509E64700224A4D7&affID=121128&tsp=4939
IE - HKU\S-1-5-21-2028594414-1911971548-3955386324-1004\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&pid=512&r=2013/07/09&hid=2209213141&lg=EN&cc=PL&unqvl=24
FF - HKLM\Software\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF - HKLM\Software\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\uyuwsd8fq@yg-eccmeao.com: C:\Users\abc\AppData\Roaming\Mozilla\Firefox\Profiles\bz9yexmk.abc\extensions\uyuwsd8fq@yg-eccmeao.com [2013-07-09 22:44:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\zzzxouyy@hgmt-.co.uk: C:\Users\abc\AppData\Roaming\Mozilla\Firefox\Profiles\bz9yexmk.abc\extensions\zzzxouyy@hgmt-.co.uk [2013-07-09 22:45:19 | 000,000,000 | ---D | M]
[2013-07-10 17:37:17 | 000,000,000 | ---D | M] (DealPly Shopping) -- C:\Users\abc\AppData\Roaming\mozilla\Firefox\Profiles\bz9yexmk.abc\Extensions\{906000a4-88d9-4d52-b209-7a772970d91f}
[2013-07-09 22:44:48 | 000,000,000 | ---D | M] (safue ssave) -- C:\Users\abc\AppData\Roaming\mozilla\Firefox\Profiles\bz9yexmk.abc\Extensions\uyuwsd8fq@yg-eccmeao.com
[2013-07-09 22:45:19 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Users\abc\AppData\Roaming\mozilla\Firefox\Profiles\bz9yexmk.abc\Extensions\zzzxouyy@hgmt-.co.uk
CHR - Extension: No name found = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.2_0\
CHR - Extension: No name found = C:\Users\abc\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0\
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll File not found
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll File not found
O4 - HKU\S-1-5-21-2028594414-1911971548-3955386324-1203..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O20 - AppInit_DLLs: (c:\progra~2\safesa~1\sprote~1.dll) - c:\Program Files (x86)\SafeSaver\sprotector.dll ()
O20 - AppInit_DLLs: (c:\progra~2\websea~1\sprote~1.dll) - c:\Program Files (x86)\WebSearch\sprotector.dll ()
[2013-07-10 21:08:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
[2013-07-10 21:08:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegClean Pro
[2013-07-10 21:08:20 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\systweak
[2013-07-10 21:07:54 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\BabSolution
[2013-07-10 21:07:52 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\mixidj
[2013-07-10 17:37:19 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\DealPlyLive
[2013-07-10 17:37:19 | 000,000,000 | ---D | C] -- C:\ProgramData\DealPlyLive
[2013-07-10 17:37:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DealPlyLive
[2013-07-10 17:37:17 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Dealply
[2013-07-10 17:37:16 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
[2013-07-10 17:37:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DealPly
[2013-07-10 17:36:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013-07-10 17:36:55 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013-07-10 17:36:51 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserDefender
[2013-07-10 17:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Device Doctor
[2013-07-10 17:36:23 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Device Doctor
[2013-07-10 17:36:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Device Doctor
[2013-07-10 17:36:13 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Roaming\Babylon
[2013-07-10 17:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2013-07-10 17:35:40 | 000,000,000 | ---D | C] -- C:\Users\abc\AppData\Local\SlimWare Utilities Inc
[2013-07-10 17:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2013-07-10 17:34:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlimDrivers
[2013-07-09 22:55:20 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013-07-09 22:47:09 | 000,313,856 | ---- | C] (Halfdone Development) -- C:\Users\abc\Desktop\UnknownDevices.exe
[2013-07-09 22:45:29 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp
[2013-07-09 22:45:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab
[2013-07-09 22:45:19 | 000,000,000 | ---D | C] -- C:\ProgramData\SearchNewTab
[2013-07-09 22:45:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebSearch
[2013-07-09 22:44:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SafeSaver
[2013-07-09 22:44:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\safue ssave
[2013-07-09 22:44:48 | 000,000,000 | ---D | C] -- C:\ProgramData\safue ssave
[2013-07-09 22:44:32 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
:Files
C:\Windows\tasks\*.*
:Commands
[clearallrestorepoints]
[emptytemp]