:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&mntrId=f4268b87000000000000001fd043bf96&tlver=1.4.19.19&ss=1&affID=17981
IE - HKLM\..\URLSearchHook: {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found
IE - HKLM\..\URLSearchHook: {28272685-df84-48d7-9589-f91a162b4e94} - No CLSID value found
IE - HKLM\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - No CLSID value found
IE - HKLM\..\URLSearchHook: {8a6264b5-a8f2-494b-8f37-cf898a763e42} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&SearchSource=4&ctid=CT3031607
IE - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzutDtDtC0F0DtDyEtA0B0FzyyCzz0BzzyBtN0D0Tzu0CtBzzyDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1675729507
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&barid={0392150C-5BF5-11E1-A4F3-001FD043BF96}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKCU\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - No CLSID value found
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}?babsrc=browsersearch&AF=15627
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{0E90368D-C116-41D0-AB13-6A67B47455A3}&mid=66ed972fc23047d09428d15696a75665-82aaeaf3152a1cb8d577922f9d99ebf260c7cfd4&lang=pl&ds=cv011&pr=sa&d=2012-07-12 17:00:28&v=12.2.5.32&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKCU\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzutDtDtC0F0DtDyEtA0B0FzyyCzz0BzzyBtN0D0Tzu0CtBzzyDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1675729507
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&barid={0392150C-5BF5-11E1-A4F3-001FD043BF96}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
FF - prefs.js..browser.search.defaultenginename: "Funmoods"
FF - prefs.js..browser.search.defaultthis.engineName: "Free Lunch Design Customized Web Search"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..extensions.enabledAddons:
ffxtlbr@funmoods.com:1.5.1
FF - prefs.js..extensions.enabledItems: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}:2.7.2.0
FF - prefs.js..extensions.enabledItems:
DTToolbar@toolbarnet.com:1.1.4.0024
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&q="
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll File not found
[2010-07-25 10:24:03 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012-11-07 10:57:51 | 000,000,000 | ---D | M] (Free Lunch Design Community Toolbar) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2012-08-31 12:03:57 | 000,000,000 | ---D | M] (kikin plugin (CounterStrike2D Edition)) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
[2012-09-02 13:16:15 | 000,000,000 | ---D | M] (ADDICT-THING) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\50434a7988557@50434a7988591.info
[2012-02-17 13:13:01 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\DTToolbar@toolbarnet.com
[2012-10-12 13:12:51 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\ffxtlbr@funmoods.com
[2012-10-07 12:56:29 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Bogusława\AppData\Roaming\mozilla\Firefox\Profiles\knwj4gx1.default\extensions\OneClickDownload@OneClickDownload.com
[2010-06-24 17:18:30 | 000,000,937 | ---- | M] () -- C:\Users\Bogusława\AppData\Roaming\mozilla\firefox\profiles\knwj4gx1.default\searchplugins\conduit.xml
[2011-02-14 10:51:59 | 000,002,059 | ---- | M] () -- C:\Users\Bogusława\AppData\Roaming\mozilla\firefox\profiles\knwj4gx1.default\searchplugins\daemon-search.xml
[2012-10-12 13:13:01 | 000,002,333 | ---- | M] () -- C:\Users\Bogusława\AppData\Roaming\mozilla\firefox\profiles\knwj4gx1.default\searchplugins\Funmoods.xml
[2012-09-19 19:54:01 | 000,004,007 | ---- | M] () -- C:\Users\Bogusława\AppData\Roaming\mozilla\firefox\profiles\knwj4gx1.default\searchplugins\sweetim.xml
[2012-10-27 11:15:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-09-03 13:16:08 | 000,003,771 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2011-12-27 17:05:20 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2010-09-02 09:09:28 | 000,002,486 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml
[2012-03-13 16:02:30 | 000,002,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011-12-15 14:18:13 | 000,002,415 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
O2 - BHO: (no name) - {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found.
O2 - BHO: (no name) - {28272685-df84-48d7-9589-f91a162b4e94} - No CLSID value found.
O2 - BHO: (no name) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No CLSID value found.
O2 - BHO: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O2 - BHO: (no name) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - No CLSID value found.
O2 - BHO: (no name) - {8a6264b5-a8f2-494b-8f37-cf898a763e42} - No CLSID value found.
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (no name) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll File not found
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {08d6b0b4-c132-470d-a8e2-aa2e9c3851c9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0D704FAD-66E9-4F0A-BFED-4F665770DDB3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {28272685-df84-48d7-9589-f91a162b4e94} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8a6264b5-a8f2-494b-8f37-cf898a763e42} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {28272685-DF84-48D7-9589-F91A162B4E94} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ROC_ROC_JULY_P1] "C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 File not found
O4 - HKLM..\Run: [Sudoku] File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; BTRS26718; GTB6.6; EasyBits GO v1.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; .NET CLR 1.1.4322; .NET4.0C)" -"http://www.wyspagier.pl/gry/gry-wyscigowe/mini_wyscig_zip_zaps.html" File not found
O4 - Startup: C:\Users\Bogusława\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RazossUpdater.lnk = C:\Users\Bogusława\AppData\Local\Razoss\Application\RazossUpdater.exe (Razoss Bar)
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : @C:\Program Files\Techland\English Translator XT\InternetTranslator\InternetTranslator.dll,-103 - {B46B0919-62BA-4D99-A5C4-916B57A6805C} - Reg Error: Key error. File not found
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
Dostępne tylko dla zarejestrowanych użytkowników (Shockwave ActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 1.6.0_01)
:Services
gusvc
gupdate
gupdatem
:Files
C:\Program Files\Google\Update
C:\Windows\tasks\*.*
C:\Users\Bogusława\AppData\Roaming\Aeria Games & Entertainment
C:\Users\Bogusława\AppData\Roaming\BabylonToolbar
C:\Users\Bogusława\AppData\Roaming\ESET
C:\Users\Bogusława\AppData\Roaming\kikin
C:\Users\Bogusława\AppData\Roaming\Optimizer Pro
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
:Commands
[clearallrestorepoints]
[emptytemp]