:OTL
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKLM\..\SearchScopes\{8B0E4886-5F85-48DE-AA78-5D6CC2C98B91}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes\{5F970FDE-702B-4ef9-920C-5F2848A5AF26}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes\{73343B8B-6F39-4B12-8E46-41CA67AA9F5D}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&affID=112555&tt=010712_2&babsrc=SP_ss&mntrId=4c9500a0000000000000000e2ecf9e76
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes\{8B0E4886-5F85-48DE-AA78-5D6CC2C98B91}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\SearchScopes\{D72305CE-F570-490F-BC29-224240006E5B}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledAddons: autoproxy%40autoproxy.org:0.4b2.2013051811
FF - prefs.js..extensions.enabledItems:
autoproxy@autoproxy.org:0.4b2.2011041023
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF
[2012-05-05 00:45:19 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\vd92m6wu.default\extensions\ietab@ip.cn
[2013-05-25 17:44:49 | 000,191,061 | ---- | M] () (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\extensions\autoproxy@autoproxy.org.xpi
[2013-07-07 16:57:01 | 000,320,068 | ---- | M] () (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
[2013-07-19 13:35:00 | 000,223,750 | ---- | M] () (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2013-05-10 08:40:01 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011-06-26 18:37:55 | 000,002,071 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\searchplugins\absearch-search.xml
[2012-06-14 10:01:31 | 000,001,820 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\searchplugins\bing.xml
[2012-12-05 01:39:12 | 000,010,339 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\searchplugins\duckduckgo-1.xml
[2012-12-05 01:39:05 | 000,010,339 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\searchplugins\duckduckgo.xml
[2012-10-02 21:12:48 | 000,000,792 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mozilla\firefox\profiles\vd92m6wu.default\searchplugins\startsear.xml
[2011-10-27 15:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
O3:
64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (no name) - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKU\S-1-5-21-1653755803-266078052-2015987074-1000\..\Toolbar\WebBrowser: (no name) - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No CLSID value found.
O4 - HKU\S-1-5-21-1653755803-266078052-2015987074-1000..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:
64bit: - Extra context menu item: E&ksportuj do programu Microsoft Excel -
res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:
64bit: - Extra context menu item: Wyślij &do programu OneNote -
res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel -
res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Wyślij &do programu OneNote -
res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 10.25.2)
[2013-07-18 19:43:21 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\AVG2013
[2013-07-18 19:42:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013-07-18 19:42:00 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013-07-18 19:42:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013-07-18 19:41:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2013-07-18 19:39:08 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Local\Avg2013
[2012-08-29 14:52:56 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\.techniclauncher
[2013-07-18 19:43:21 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVG2013
[2012-03-25 02:14:03 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BITS
[2011-10-09 18:57:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BSplayer
[2011-10-04 13:22:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BSplayer Pro
[2012-05-26 11:15:26 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DisneyInteractiveStudios
[2012-05-08 22:19:09 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Drivers For Free
[2012-03-08 21:01:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\EurekaLog
[2012-08-15 21:13:17 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\fizzy
[2012-03-25 10:37:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FlashgetSetup
[2011-11-21 14:52:01 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GetRightToGo
[2011-07-07 21:17:33 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GHISLER
[2011-10-22 11:17:33 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\HTML Executable
[2011-10-14 18:06:39 | 000,000,000 | -H-D | M] -- C:\Users\admin\AppData\Roaming\IFViewer
[2011-10-20 10:47:01 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\iPlus
[2012-11-27 20:59:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\IrfanView
[2011-05-21 20:44:35 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Leadertech
[2012-06-25 23:04:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LG Electronics
[2011-07-10 19:03:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Lionhead Studios
[2012-10-14 17:15:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Mirillis
[2011-10-09 16:27:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MusicNet
[2011-09-05 10:38:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\NapiProjekt
[2012-05-23 23:35:00 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nuclear Coffee
[2012-02-01 12:49:17 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Pokemon Online
[2012-09-22 17:14:57 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\skyz
[2012-03-23 23:38:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SPORE
[2012-03-17 18:58:17 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Teeworlds
[2012-12-01 14:53:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TuneUp Software
[2012-03-15 21:10:47 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\VBA-M
[2012-07-07 14:19:01 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\YourFileDownloader
[2012-06-25 23:04:14 | 000,000,000 | -H-D | M] -- C:\Users\admin\AppData\Roaming\{D94BA408-F110-488B-A65E-3AE7945F79E6}
[2013-02-09 16:07:01 | 000,000,000 | ---D | M] -- C:\Users\MDM\AppData\Roaming\skyz
[2013-01-08 19:22:31 | 000,000,000 | ---D | M] -- C:\Users\MDM\AppData\Roaming\TuneUp Software
:Services
gupdate
gupdatem
:Files
C:\Program Files (x86)\Google\Update
C:\Windows\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]