:OTL
DRV - [2013-09-17 13:54:26 | 000,201,312 | ---- | M] (Kaspersky Lab, GERT) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\71646462.sys -- (35696009)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKLM\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=LENIE
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
Dostępne tylko dla zarejestrowanych użytkowników [binary data]
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
Dostępne tylko dla zarejestrowanych użytkownikówIE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=LENIE
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&affID=119294&tt=gc_&babsrc=SP_ss_din2g&mntrId=605D00216B3B9D44
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&locale=en_US
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&rlz=1I7PCTA_pl&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" =
Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}
IE - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\PAWEL\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
O2 - BHO: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found.
O3 - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-777265772-1934788495-1899270973-1000\..\Toolbar\WebBrowser: (no name) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - No CLSID value found.
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [tuto4pc_pl_17] File not found
O4 - HKLM..\Run: [] File not found
O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
[2013-09-17 15:31:42 | 000,245,760 | ---- | C] (Ask.com) -- C:\Program Files\Uninstall Ask Toolbar.dll
[2013-09-17 15:10:14 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013-09-17 13:56:50 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\PROGRAMY\program\Desktop\Autoruns
[2013-09-17 13:52:54 | 002,748,256 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\PAWEL\PROGRAMY\program\Desktop\tdsskiller.exe
[2013-09-17 13:52:51 | 002,623,656 | ---- | C] (VS Revo Group Ltd.) -- C:\Users\PAWEL\PROGRAMY\program\Desktop\revosetup.exe
[2013-09-17 13:48:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2013-09-16 15:36:26 | 000,861,184 | ---- | C] (Disc Soft Ltd) -- C:\ProgramData\mrprotection.exe
[2013-09-14 09:31:45 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\AppData\Local\avgchrome
[2013-09-11 11:09:25 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\AppData\Roaming\1J1F1H1E2Y2Z1P1C1B2W1L1T2ZtF1E1I
[2013-09-11 11:08:56 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\AppData\Roaming\Funmoods
[2013-09-11 10:57:43 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\AppData\Local\BonanzaDealsLive
[2013-09-11 10:57:43 | 000,000,000 | ---D | C] -- C:\Program Files\BonanzaDealsLive
[2013-09-11 10:57:36 | 000,000,000 | ---D | C] -- C:\Users\PAWEL\AppData\Local\eorezo
[2013-09-11 10:57:15 | 000,000,000 | ---D | C] -- C:\Program Files\BonanzaDeals
[2013-08-20 22:57:45 | 000,000,000 | ---D | C] -- C:\9e2577ab7de1f7e73b5bb5f7d2aae3
[2010-11-03 12:33:35 | 000,695,296 | ---- | C] (AnjoCaido) -- C:\Users\PAWEL\AppData\Roaming\MinecraftSP.exe
[2013-09-17 15:06:30 | 000,000,574 | ---- | M] () -- C:\Users\PAWEL\AppData\Local\RT73_{A3506063-A872-443C-979F-B4E29EDA99BD}_ap
[2013-09-17 15:01:35 | 000,000,739 | ---- | M] () -- C:\Users\PAWEL\AppData\Local\RT73_{A3506063-A872-443C-979F-B4E29EDA99BD}_prof
[2013-09-17 13:28:20 | 000,550,371 | ---- | M] () -- C:\Users\PAWEL\PROGRAMY\program\Desktop\Autoruns.zip
[2013-09-17 13:27:54 | 002,748,256 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\PAWEL\PROGRAMY\program\Desktop\tdsskiller.exe
[2013-09-16 15:36:26 | 000,000,625 | ---- | M] () -- C:\Users\Public\Desktop\Internet Security 2013.lnk
[2013-09-11 11:09:01 | 006,119,688 | ---- | M] (Power Software Ltd) -- C:\Users\PAWEL\Documents\PowerISO 5.7.exe
[2013-09-11 10:56:16 | 000,153,926 | ---- | M] () -- C:\Users\PAWEL\Documents\DAEMON Tools PL 4.30.1.exe
[2013-07-27 22:21:55 | 000,093,672 | ---- | C] () -- C:\Users\PAWEL\AppData\Roaming\Uninstal.exe
[2013-04-18 09:37:15 | 000,114,176 | ---- | C] () -- C:\Users\PAWEL\AppData\Roaming\BabMaint.exe
[2009-10-07 18:02:21 | 000,087,608 | ---- | C] () -- C:\Users\PAWEL\AppData\Roaming\inst.exe
[2013-09-11 11:09:25 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\1J1F1H1E2Y2Z1P1C1B2W1L1T2ZtF1E1I
[2010-10-23 18:47:42 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Ashampoo
[2009-12-01 21:45:53 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Audacity
[2013-04-16 21:44:49 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\BabSolution
[2013-02-26 19:14:51 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Babylon
[2012-11-09 09:36:09 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\blueconnect
[2010-01-04 15:24:25 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\CDBurnerXP_Soft
[2010-02-09 14:29:41 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\City Interactive
[2010-02-09 16:22:45 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\COWON
[2013-04-16 21:41:07 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\DealPly
[2009-03-07 00:06:53 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Desktop Sidebar
[2009-12-11 23:59:05 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\FRISK Software
[2013-09-11 11:08:56 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Funmoods
[2009-02-17 22:34:23 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\InterVideo
[2012-07-13 15:16:44 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\iPlus
[2009-03-06 19:27:58 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\JLC's Software
[2012-12-10 20:04:11 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Mikrotik
[2009-12-10 23:29:48 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\NCH Swift Sound
[2011-06-28 15:24:33 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\OpenFM
[2009-03-04 19:38:36 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\PeerNetworking
[2010-03-31 18:53:02 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\PhotoFiltre
[2009-10-04 14:46:46 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Programer
[2009-03-06 19:21:31 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\RaimaRadio
[2010-03-30 19:56:51 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Samsung
[2010-07-16 17:26:50 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\smc
[2010-10-12 18:54:00 | 000,000,000 | -HSD | M] -- C:\Users\PAWEL\AppData\Roaming\SystemProc
[2010-03-31 18:31:44 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\TigerPlayer
[2010-07-26 22:10:00 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Ubisoft
[2013-07-15 12:51:59 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Unity
[2010-12-02 18:26:52 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\uTorrent
[2009-10-07 18:04:56 | 000,000,000 | ---D | M] -- C:\Users\PAWEL\AppData\Roaming\Vso
:Services
gupdate
gupdatem
:Files
C:\Users\PAWEL\AppData\LocalLow\Unity
C:\Program Files\Google\Update
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
:Commands
[clearallrestorepoints]
[emptytemp]