:OTL
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKU\S-1-5-21-3769642883-322224420-2549721243-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-3769642883-322224420-2549721243-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-3769642883-322224420-2549721243-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
FF - prefs.js..extensions.enabledAddons:
ffxtlbr@funmoods.com:1.5.1
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2012-09-09 20:45:27 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\31b7srmn.default\extensions\ffxtlbr@babylon.com
[2012-09-09 20:45:27 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\31b7srmn.default\extensions\ffxtlbr@funmoods.com
[2012-09-04 19:12:23 | 000,002,339 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\31b7srmn.default\searchplugins\Search.xml
[2012-10-29 19:16:10 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-09-04 19:11:02 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
[2012-11-02 17:07:49 | 000,000,000 | ---D | C] -- C:\ProgramData\OnlineUpdate
[2012-11-07 19:48:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012-10-20 21:45:29 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Local\{CDFD1430-21D4-4448-9365-83581115C362}
[2012-10-20 21:45:29 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Local\{690088B3-B8EB-4203-9AF5-CA5BFCF6C6EF}
@Alternate Data Stream - 368 bytes -> C:\Users\Patryk\Documents\boot:$WIMMOUNTDATA
@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:07BF512B
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:5D458568
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:6CC69D3C
:Files
C:\Windows\tasks\*.*
C:\Users\Patryk\AppData\Roaming\BabylonToolbar
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]