:OTL
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2618378051-2944415511-2799995395-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-2618378051-2944415511-2799995395-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2618378051-2944415511-2799995395-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-2618378051-2944415511-2799995395-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&affID=119816&babsrc=SP_ss&mntrId=a067f4980000000000001c4bd61bac61
FF - prefs.js..browser.startup.homepage: "http://www.gazeta.pl/0,0.html?p=143"
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
[2013-02-26 23:23:18 | 000,000,000 | ---D | M] (MediaBar) -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\ju309biq.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
[2013-05-15 20:18:35 | 000,000,000 | ---D | M] (Iplex to ALLPlayer) -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\ju309biq.default\extensions\IplextoALL@ALLPlayer.org
[2013-06-14 10:42:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\ju309biq.default\extensions\staged
[2013-02-26 23:23:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\wsn75w2h.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013-02-26 23:23:27 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\wsn75w2h.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2013-02-26 23:23:21 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\dmnd\AppData\Roaming\mozilla\Firefox\Profiles\pufqo070.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011-06-24 21:20:09 | 000,010,043 | ---- | M] () (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\firefox\profiles\ju309biq.default\extensions\IplextoALL@ALLPlayer.org.xpi
[2012-02-16 21:45:17 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\firefox\profiles\ju309biq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013-01-07 13:04:44 | 000,269,905 | ---- | M] () (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\firefox\profiles\ju309biq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013-06-14 10:42:29 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\firefox\profiles\ju309biq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013-06-14 10:42:28 | 000,282,569 | ---- | M] () (No name found) -- C:\Users\dmnd\AppData\Roaming\mozilla\firefox\profiles\ju309biq.default\extensions\staged\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013-03-04 17:43:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions\ffxtlbr@babylon.com
[2013-06-14 11:37:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\ffxtlbr@babylon.com
[2013-03-04 17:43:34 | 000,006,484 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
O4 - HKU\S-1-5-21-2618378051-2944415511-2799995395-1000..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\dmnd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\trz12F3.tmp (Solar)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
[2013-08-16 23:13:08 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2013-08-22 17:28:32 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp
[2013-08-22 17:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2013-02-26 23:22:11 | 000,000,000 | ---D | M] -- C:\Users\dmnd\AppData\Roaming\Asus WebStorage
[2013-02-26 23:20:45 | 000,000,000 | ---D | M] -- C:\Users\dmnd\AppData\Roaming\EeeStorageUploader
[2013-02-26 23:20:52 | 000,000,000 | ---D | M] -- C:\Users\dmnd\AppData\Roaming\GlarySoft
[2013-02-26 23:22:02 | 000,000,000 | ---D | M] -- C:\Users\dmnd\AppData\Roaming\Uniblue
:Services
gupdate
gupdatem
:Files
C:\Windows\tasks\*.*
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]