:OTL
SRV - File not found [Auto | Unknown] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - File not found [Auto | Unknown] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
DRV - File not found [Kernel | On_Demand | Running] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (XDva400)
DRV - File not found [File_System | On_Demand | Stopped] -- -- (WinRing0_1_2_0)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (TuneUpUtilitiesDrv)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslf0e4d0e2)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\justyna\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012-12-11 23:16:00 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012-12-11 23:15:59 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012-12-11 23:15:59 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&affID=110819&tt=060612_5_&babsrc=SP_ss&mntrId=4a208fb3000000000000001a73ee40f6
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&loc=IB_DS&a=6R8MPYwqi2&i=26
IE - HKU\S-1-5-21-709587900-2880546135-179499377-1000\..\SearchScopes\{D1D97302-6E8A-4BE1-986B-40A20800C27C}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=YYYYYYYYPL&apn_uid=7A872CD3-3490-489F-AB24-FA76B5080924&apn_sauid=80FA9F53-D142-46BA-8E0F-B945C200A324
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.order.1: "v9"
FF - prefs.js..keyword.URL: "http://mystart.incredibar.com/mb128/?loc=IB_DS&a=6R8MPYwqi2&&i=26&search="
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\justyna\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\justyna\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
[2012-11-30 18:37:15 | 000,002,203 | ---- | M] () -- C:\Users\justyna\AppData\Roaming\mozilla\firefox\profiles\qyherlnu.default\searchplugins\MyStart Search.xml
[2012-06-07 12:50:07 | 000,002,352 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012-11-17 22:38:40 | 000,000,402 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
[2012-12-13 18:30:01 | 011,563,944 | ---- | C] (OPSWAT, Inc.) -- C:\Users\justyna\Desktop\AppRemover.exe
[2012-12-12 21:15:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2012-12-12 17:43:01 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Roaming\ESET
[2012-12-12 17:43:01 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Local\ESET
[2012-12-12 05:37:00 | 000,000,000 | ---D | C] -- C:\CFLog
[2012-12-11 22:11:14 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Roaming\Avira
[2012-12-11 22:06:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012-12-11 22:05:48 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012-12-11 22:05:46 | 000,134,336 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012-12-11 22:05:46 | 000,083,944 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012-12-11 22:05:46 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012-12-11 22:05:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012-12-11 21:16:01 | 000,161,312 | ---- | C] (BitDefender LLC) -- C:\Windows\System32\drivers\gzflt.sys
[2012-12-11 21:16:00 | 000,343,456 | ---- | C] (BitDefender S.R.L.) -- C:\Windows\System32\drivers\trufos.sys
[2012-12-11 19:15:22 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Roaming\liQeNSoft
[2012-12-11 19:15:22 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Local\liQeNSoft
[2012-12-11 19:06:11 | 000,000,000 | ---D | C] -- C:\ProgramData\BDLogging
[2012-12-11 19:05:56 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\capicom.dll
[2012-12-11 19:05:17 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Roaming\Bitdefender
[2012-12-11 19:03:59 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Roaming\QuickScan
[2012-12-11 18:51:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bitdefender
[2012-12-07 06:31:00 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure uninstallationtool
[2012-12-07 06:30:59 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure-UninstallationTool
[2012-12-05 05:35:57 | 000,000,000 | ---D | C] -- C:\Users\justyna\AppData\Local\temp
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:6343C281
:Files
$RECYCLE.BIN /alldrives
C:\Windows\erdnt
C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
C:\ProgramData\F-Secure
C:\Temp
C:\Windows\System32\AI_RecycleBin
C:\Program Files\Google\Update
C:\Users\justyna\AppData\Local\Google\Update
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]