:OTL
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkowników{6B32CAAF-F678-4EBA-B818-E15F810525E2}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&barid={6B32CAAF-F678-4EBA-B818-E15F810525E2}
IE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&affID=114506&tt=4212_2&babsrc=SP_clro&mntrId=7c62df7b000000000000002618bab28a
IE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&loc=IB_DS&a=6R8wFOSzNd&i=26
IE - HKU\S-1-5-21-2220664200-355283622-366406444-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&barid={6B32CAAF-F678-4EBA-B818-E15F810525E2}
FF - prefs.js..browser.search.defaultenginename: "My Web Search"
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=2CBCB08B-FD17-48EB-B50E-DAB337905201&n=77ee4105&ind=2012102917&id=HJxdm007YYpl&ptnrS=HJxdm007YYpl&si=CN6ehvfJprMCFcy23god43IAYQ&searchfor="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=2CBCB08B-FD17-48EB-B50E-DAB337905201&n=77ee4105&ind=2012102917&id=HJxdm007YYpl&ptnrS=HJxdm007YYpl&si=CN6ehvfJprMCFcy23god43IAYQ&searchfor="
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll File not found
FF - prefs.js..extensions.enabledAddons: 4zffxtbr@VideoDownloadConverter_4z.com:2.50.0.51741
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012-08-31 18:59:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012-08-31 18:59:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\4zffxtbr@VideoDownloadConverter_4z.com: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin [2012-11-07 19:10:32 | 000,000,000 | ---D | M]
[2012-10-29 17:30:16 | 000,009,650 | ---- | M] () -- C:\Users\Karol\AppData\Roaming\mozilla\firefox\profiles\mk3iiw7w.default\searchplugins\my-web-search.xml
[2012-08-21 10:39:12 | 000,004,007 | ---- | M] () -- C:\Users\Karol\AppData\Roaming\mozilla\firefox\profiles\mk3iiw7w.default\searchplugins\sweetim.xml
[2012-11-07 19:10:32 | 000,000,000 | ---D | M] (VideoDownloadConverter) -- C:\PROGRAM FILES (X86)\VIDEODOWNLOADCONVERTER_4Z\BAR\1.BIN
[2012-08-31 18:59:08 | 000,000,000 | ---D | M] (Web Assistant) -- C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
[2012-05-31 13:25:34 | 000,190,664 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npVividasPlayer.dll
[2012-10-21 11:33:39 | 000,006,522 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
CHR - Extension: Montiera Chrome Toolbar = C:\Users\Karol\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmbgdmijgopggjaelphhajpjldacbnba\1.0_0\
CHR - Extension: Web Assistant = C:\Users\Karol\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\
O3 - HKLM\..\Toolbar: (VideoDownloadConverter) - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
[2012-10-29 17:30:16 | 000,000,000 | ---D | C] -- C:\Users\Karol\AppData\Local\VideoDownloadConverter_4z
[2012-10-29 16:50:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Download Converter
[2012-10-29 16:50:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Video Download Converter
[2012-10-29 16:50:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoDownloadConverter_4z
[2012-10-14 18:19:53 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012-11-06 18:10:15 | 000,099,318 | ---- | M] () -- C:\Users\Karol\Pliki.zip
[2012-11-06 18:08:59 | 002,413,460 | ---- | M] () -- C:\Users\Karol\AutoRuns.arn
[2012-11-06 18:02:54 | 002,385,892 | ---- | M] () -- C:\Users\Karol\WinRaR.arn
:Files
C:\Program Files (x86)\Google\Update
C:\Windows\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]